mjd59
2012-06-21, 12:31
hi, i am no computer experte but looking at these file of mine seem to tell me either 1, i have a live hacker. 2. an over suspisious girlfriend. 3, some form of goverment / public protection [as they would call it] program. i ddo also think my modem has being hijacked and maybe reading my cell phone info . i do have actual files which are in need of analistic eyes , i could be just paranoid ????/ please help before i go mad chasing this around my c drive
thanks
mick
p.s dds has been renamed my porn to try throw off any chance of it been tampered
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by admin at 18:55:08 on 2012-06-21
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.61.1033.18.3316.1110 [GMT 10:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\tcpsvcs.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\AMT\UNS.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\sdclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - c:\program files\internet explorer\iedvtool.dll
uRun: [HijackThis startup scan] c:\program files\trend micro\hijackthis\HijackThis.exe /startupscan
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [SRSAENotifier] c:\program files\srs labs\srs audio essentials\AENotifier.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [atchk] "c:\program files\intel\amt\atchk.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Trend Micro RUBotted V2.0 Beta] c:\program files\trend micro\rubotted\RUBottedGUI.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{1FF946B5-3569-49FD-B766-744DCCA3A297} : DhcpNameServer = 192.168.0.1
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 ci05knef;Vba32 Armour Driver;c:\windows\system32\drivers\ci05knef.sys [2012-6-19 35904]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 171064]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-5-20 654408]
R2 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-3-26 214952]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-21 50704]
R2 RUBotSrv;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\RUBotSrv.exe [2012-6-20 439632]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2012-3-17 1153368]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2011-12-15 2521880]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-5-20 22344]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 74112]
R3 SRS_AE_Service;SRS Audio Essentials;c:\windows\system32\drivers\SRS_AE_i386.sys [2012-5-1 404256]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-3-23 136176]
S2 SRSHDAudioService;SRS HDAudio Lab Service;"c:\program files\common files\srs labs\srs hd audio lab service\srsaudiolabservice.exe" --> c:\program files\common files\srs labs\srs hd audio lab service\SRSAudioLabService.exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-4 257696]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2012-5-26 30312]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-3-23 136176]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2011-6-13 267568]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2012-5-26 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2012-5-26 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2012-5-26 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2012-5-26 114280]
SUnknown MpKsl5cb10997;MpKsl5cb10997; [x]
.
=============== Created Last 30 ================
.
2012-06-21 08:42:12 6762896 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{ad17be3a-25e4-497d-be8b-5553a624810c}\mpengine.dll
2012-06-20 12:15:59 -------- d-----w- c:\programdata\Trend Micro
2012-06-20 12:05:55 -------- d-----w- c:\program files\WinPcap
2012-06-20 11:01:43 -------- d-----w- c:\program files\Safer Networking
2012-06-20 08:42:26 6762896 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-06-19 14:12:04 -------- d-----w- c:\users\admin\appdata\local\MPlayer
2012-06-19 11:31:27 388096 ----a-r- c:\users\admin\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-06-19 11:31:25 -------- d-----w- c:\program files\Trend Micro
2012-06-19 09:29:57 35904 ----a-w- c:\windows\system32\drivers\ci05knef.sys
2012-06-13 03:29:37 713784 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2012-06-13 03:29:37 713784 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f469b385-4890-4ffe-87a5-3241d146f901}\gapaengine.dll
2012-06-12 18:19:06 -------- d-----w- c:\users\admin\appdata\local\Apps
2012-06-12 07:25:58 -------- d-----w- c:\users\admin\appdata\local\temp
2012-06-12 07:25:08 -------- d-sh--w- C:\$RECYCLE.BIN
2012-06-10 16:18:51 98816 ----a-w- c:\windows\sed.exe
2012-06-10 16:18:51 518144 ----a-w- c:\windows\SWREG.exe
2012-06-10 16:18:51 256000 ----a-w- c:\windows\PEV.exe
2012-06-10 16:18:51 208896 ----a-w- c:\windows\MBR.exe
2012-06-08 13:42:43 -------- d-----w- c:\windows\system32\appmgmt
2012-06-08 07:36:44 -------- d-----w- c:\program files\HP
2012-06-06 12:36:38 -------- d-----w- c:\users\admin\appdata\local\Samsung
2012-06-06 12:36:23 -------- d-----w- c:\users\admin\appdata\roaming\Samsung
2012-06-06 12:04:42 -------- d-----w- c:\users\admin\appdata\local\Adobe
2012-06-06 11:38:24 -------- d-----w- c:\users\admin\appdata\roaming\Malwarebytes
2012-06-04 18:24:05 -------- d-----w- c:\program files\Yontoo
2012-06-04 18:24:02 -------- d-----w- c:\programdata\Tarma Installer
2012-06-03 07:42:50 -------- d-----w- c:\programdata\FilesOpened
2012-06-03 07:41:41 -------- d-----w- c:\programdata\RegWork
2012-06-03 07:41:28 -------- d-----w- c:\program files\Ask.com
2012-06-03 07:41:12 -------- d-----w- c:\program files\RegWork
2012-05-30 09:38:19 -------- d-----w- c:\program files\iPod
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2012-05-26 11:17:39 -------- d-----w- C:\Temp
2012-05-26 00:37:30 30312 ----a-w- c:\windows\system32\drivers\ssadadb.sys
2012-05-26 00:37:30 1416680 ----a-w- c:\windows\system32\WdfCoInstaller01005.dll
2012-05-26 00:37:30 1416680 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01005.dll
2012-05-26 00:37:30 136808 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
2012-05-26 00:37:30 12776 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
2012-05-26 00:37:30 121064 ----a-w- c:\windows\system32\drivers\ssadbus.sys
2012-05-26 00:37:30 114280 ----a-w- c:\windows\system32\drivers\ssadserd.sys
2012-05-26 00:37:30 10472 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys
2012-05-26 00:37:30 10472 ----a-w- c:\windows\system32\drivers\ssadcm.sys
2012-05-26 00:37:30 10344 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys
2012-05-26 00:37:30 10344 ----a-w- c:\windows\system32\drivers\ssadwh.sys
2012-05-26 00:36:38 14920 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
2012-05-26 00:36:38 132424 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2012-05-26 00:36:38 12616 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2012-05-26 00:36:38 12616 ----a-w- c:\windows\system32\drivers\sscdcm.sys
2012-05-26 00:36:38 12488 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2012-05-26 00:36:38 12488 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2012-05-26 00:36:38 104648 ----a-w- c:\windows\system32\drivers\sscdbus.sys
2012-05-26 00:35:37 4659712 ----a-w- c:\windows\system32\Redemption.dll
2012-05-26 00:35:02 821824 ----a-w- c:\windows\system32\dgderapi.dll
2012-05-26 00:35:02 20032 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
2012-05-26 00:35:02 -------- d-----w- c:\program files\MarkAny
2012-05-26 00:33:59 -------- d-----w- c:\programdata\Samsung
2012-05-26 00:33:59 -------- d-----w- c:\program files\Samsung
2012-05-24 08:18:33 -------- d-----w- c:\program files\Morphyre
2012-05-24 07:35:28 -------- d-----w- C:\inetpub
2012-05-24 06:11:40 -------- d-----w- c:\programdata\SpeedMaxPc
.
==================== Find3M ====================
.
2012-05-31 06:57:51 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-31 06:57:51 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-17 22:45:37 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-05-17 22:35:47 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-05-17 22:35:39 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-05-17 22:29:45 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-05-17 22:24:45 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-05-15 19:51:08 2045440 ----a-w- c:\windows\system32\win32k.sys
2012-05-01 14:03:49 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-23 16:00:53 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-04-23 16:00:53 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-04-23 16:00:53 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-04-18 10:56:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2012-04-18 10:56:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
2012-04-04 05:56:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-03 08:16:12 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-03 08:16:11 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-30 12:39:11 914304 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-29 13:39:19 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
.
============= FINISH: 18:55:54.85 ===============
thanks
mick
p.s dds has been renamed my porn to try throw off any chance of it been tampered
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by admin at 18:55:08 on 2012-06-21
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.61.1033.18.3316.1110 [GMT 10:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\tcpsvcs.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Intel\AMT\UNS.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Trend Micro\RUBotted\RUBotSrv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\sdclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\RUBotted\RUBottedGUI.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Developer Tools: {1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1} - c:\program files\internet explorer\iedvtool.dll
uRun: [HijackThis startup scan] c:\program files\trend micro\hijackthis\HijackThis.exe /startupscan
mRun: [Windows Defender] c:\program files\windows defender\MSASCui.exe -hide
mRun: [SRSAENotifier] c:\program files\srs labs\srs audio essentials\AENotifier.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [atchk] "c:\program files\intel\amt\atchk.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Trend Micro RUBotted V2.0 Beta] c:\program files\trend micro\rubotted\RUBottedGUI.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/_layouts/ClientBin/ieawsdc32.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{1FF946B5-3569-49FD-B766-744DCCA3A297} : DhcpNameServer = 192.168.0.1
Notify: igfxcui - igfxdev.dll
.
============= SERVICES / DRIVERS ===============
.
R0 ci05knef;Vba32 Armour Driver;c:\windows\system32\drivers\ci05knef.sys [2012-6-19 35904]
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 171064]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-5-20 654408]
R2 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\NisSrv.exe [2012-3-26 214952]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-10-21 50704]
R2 RUBotSrv;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\RUBotSrv.exe [2012-6-20 439632]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2012-3-17 1153368]
R2 UNS;Intel(R) Active Management Technology User Notification Service;c:\program files\intel\amt\UNS.exe [2011-12-15 2521880]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-5-20 22344]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 74112]
R3 SRS_AE_Service;SRS Audio Essentials;c:\windows\system32\drivers\SRS_AE_i386.sys [2012-5-1 404256]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-3-23 136176]
S2 SRSHDAudioService;SRS HDAudio Lab Service;"c:\program files\common files\srs labs\srs hd audio lab service\srsaudiolabservice.exe" --> c:\program files\common files\srs labs\srs hd audio lab service\SRSAudioLabService.exe [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-4 257696]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2012-5-26 30312]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-3-23 136176]
S3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2011-6-13 267568]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2012-5-26 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2012-5-26 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2012-5-26 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2012-5-26 114280]
SUnknown MpKsl5cb10997;MpKsl5cb10997; [x]
.
=============== Created Last 30 ================
.
2012-06-21 08:42:12 6762896 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{ad17be3a-25e4-497d-be8b-5553a624810c}\mpengine.dll
2012-06-20 12:15:59 -------- d-----w- c:\programdata\Trend Micro
2012-06-20 12:05:55 -------- d-----w- c:\program files\WinPcap
2012-06-20 11:01:43 -------- d-----w- c:\program files\Safer Networking
2012-06-20 08:42:26 6762896 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-06-19 14:12:04 -------- d-----w- c:\users\admin\appdata\local\MPlayer
2012-06-19 11:31:27 388096 ----a-r- c:\users\admin\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-06-19 11:31:25 -------- d-----w- c:\program files\Trend Micro
2012-06-19 09:29:57 35904 ----a-w- c:\windows\system32\drivers\ci05knef.sys
2012-06-13 03:29:37 713784 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll
2012-06-13 03:29:37 713784 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{f469b385-4890-4ffe-87a5-3241d146f901}\gapaengine.dll
2012-06-12 18:19:06 -------- d-----w- c:\users\admin\appdata\local\Apps
2012-06-12 07:25:58 -------- d-----w- c:\users\admin\appdata\local\temp
2012-06-12 07:25:08 -------- d-sh--w- C:\$RECYCLE.BIN
2012-06-10 16:18:51 98816 ----a-w- c:\windows\sed.exe
2012-06-10 16:18:51 518144 ----a-w- c:\windows\SWREG.exe
2012-06-10 16:18:51 256000 ----a-w- c:\windows\PEV.exe
2012-06-10 16:18:51 208896 ----a-w- c:\windows\MBR.exe
2012-06-08 13:42:43 -------- d-----w- c:\windows\system32\appmgmt
2012-06-08 07:36:44 -------- d-----w- c:\program files\HP
2012-06-06 12:36:38 -------- d-----w- c:\users\admin\appdata\local\Samsung
2012-06-06 12:36:23 -------- d-----w- c:\users\admin\appdata\roaming\Samsung
2012-06-06 12:04:42 -------- d-----w- c:\users\admin\appdata\local\Adobe
2012-06-06 11:38:24 -------- d-----w- c:\users\admin\appdata\roaming\Malwarebytes
2012-06-04 18:24:05 -------- d-----w- c:\program files\Yontoo
2012-06-04 18:24:02 -------- d-----w- c:\programdata\Tarma Installer
2012-06-03 07:42:50 -------- d-----w- c:\programdata\FilesOpened
2012-06-03 07:41:41 -------- d-----w- c:\programdata\RegWork
2012-06-03 07:41:28 -------- d-----w- c:\program files\Ask.com
2012-06-03 07:41:12 -------- d-----w- c:\program files\RegWork
2012-05-30 09:38:19 -------- d-----w- c:\program files\iPod
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2012-05-30 09:32:09 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2012-05-26 11:17:39 -------- d-----w- C:\Temp
2012-05-26 00:37:30 30312 ----a-w- c:\windows\system32\drivers\ssadadb.sys
2012-05-26 00:37:30 1416680 ----a-w- c:\windows\system32\WdfCoInstaller01005.dll
2012-05-26 00:37:30 1416680 ----a-w- c:\windows\system32\drivers\WdfCoInstaller01005.dll
2012-05-26 00:37:30 136808 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
2012-05-26 00:37:30 12776 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
2012-05-26 00:37:30 121064 ----a-w- c:\windows\system32\drivers\ssadbus.sys
2012-05-26 00:37:30 114280 ----a-w- c:\windows\system32\drivers\ssadserd.sys
2012-05-26 00:37:30 10472 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys
2012-05-26 00:37:30 10472 ----a-w- c:\windows\system32\drivers\ssadcm.sys
2012-05-26 00:37:30 10344 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys
2012-05-26 00:37:30 10344 ----a-w- c:\windows\system32\drivers\ssadwh.sys
2012-05-26 00:36:38 14920 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
2012-05-26 00:36:38 132424 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2012-05-26 00:36:38 12616 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2012-05-26 00:36:38 12616 ----a-w- c:\windows\system32\drivers\sscdcm.sys
2012-05-26 00:36:38 12488 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2012-05-26 00:36:38 12488 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2012-05-26 00:36:38 104648 ----a-w- c:\windows\system32\drivers\sscdbus.sys
2012-05-26 00:35:37 4659712 ----a-w- c:\windows\system32\Redemption.dll
2012-05-26 00:35:02 821824 ----a-w- c:\windows\system32\dgderapi.dll
2012-05-26 00:35:02 20032 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
2012-05-26 00:35:02 -------- d-----w- c:\program files\MarkAny
2012-05-26 00:33:59 -------- d-----w- c:\programdata\Samsung
2012-05-26 00:33:59 -------- d-----w- c:\program files\Samsung
2012-05-24 08:18:33 -------- d-----w- c:\program files\Morphyre
2012-05-24 07:35:28 -------- d-----w- C:\inetpub
2012-05-24 06:11:40 -------- d-----w- c:\programdata\SpeedMaxPc
.
==================== Find3M ====================
.
2012-05-31 06:57:51 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-31 06:57:51 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-17 22:45:37 1800192 ----a-w- c:\windows\system32\jscript9.dll
2012-05-17 22:35:47 1129472 ----a-w- c:\windows\system32\wininet.dll
2012-05-17 22:35:39 1427968 ----a-w- c:\windows\system32\inetcpl.cpl
2012-05-17 22:29:45 142848 ----a-w- c:\windows\system32\ieUnatt.exe
2012-05-17 22:24:45 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2012-05-15 19:51:08 2045440 ----a-w- c:\windows\system32\win32k.sys
2012-05-01 14:03:49 180736 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-04-23 16:00:53 984064 ----a-w- c:\windows\system32\crypt32.dll
2012-04-23 16:00:53 98304 ----a-w- c:\windows\system32\cryptnet.dll
2012-04-23 16:00:53 133120 ----a-w- c:\windows\system32\cryptsvc.dll
2012-04-18 10:56:30 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2012-04-18 10:56:30 69632 ----a-w- c:\windows\system32\QuickTime.qts
2012-04-04 05:56:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-04-03 08:16:12 3602816 ----a-w- c:\windows\system32\ntkrnlpa.exe
2012-04-03 08:16:11 3550080 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-03-30 12:39:11 914304 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-03-29 13:39:19 31232 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
.
============= FINISH: 18:55:54.85 ===============