Infinite Posted May 20, 2013 ID:681769 Share Posted May 20, 2013 Hi, today I was having a look around my computer (shared by some other members of my family too) using the program Winpatrol, and I found some suspicious scheduled tasks on my system called "AutoKMSDaily.job" and "AutoKMS.job", I did some searches and it sounds like someone has installed a keygen on my computer?After investigating it further I also found these two files in the place it says AutoKMS.exe is (C:\Windows\AutoKMS.exe), one of which I attached at the bottom of the post:AutoKMS.ini (couldn't attach it because file type wasn't allowed)[SettingsID]ID=2.0.1[AutoKMS]ActAttempts=10ActivateWindows=FalseAutoRemoveKMSEmulator=FalseAutoRemoveKMSHost=FalseKMSServer=127.0.0.1Logging=TrueUseKMSEmulator=True.DDS (Ver_2012-11-20.01) - NTFS_AMD64Internet Explorer: 9.0.8112.16483 BrowserJavaVersion: 10.21.2Run by JK at 21:12:03 on 2013-05-20Microsoft Windows 7 Home Premium 6.1.7601.1.1252.61.1033.18.4066.1649 [GMT 10:00].AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}AV: Trend Micro Titanium Maximum Security 2012 *Disabled/Updated* {7193B549-236F-55EE-9AEC-F65279E59A92}SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}SP: Trend Micro Titanium Maximum Security 2012 *Disabled/Updated* {CAF254AD-0555-5A60-A05C-CD200262D02F}SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}.============== Running Processes ===============.C:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Windows\system32\svchost.exe -k RPCSSC:\Windows\system32\atiesrxx.exeC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\svchost.exe -k netsvcsC:\Program Files\Sandboxie\SbieSvc.exeC:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\system32\WLANExt.exeC:\Windows\system32\atieclxx.exeC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Windows\system32\taskeng.exeC:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exeC:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeC:\Program Files (x86)\Bluetooth Suite\adminservice.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonationC:\Program Files\Intel\iCLS Client\HeciServer.exeC:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exeC:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exeC:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exec:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exeC:\Windows\SysWOW64\PnkBstrA.exeC:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXEC:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exeC:\Windows\system32\svchost.exe -k imgsvcC:\Program Files\Trend Micro\Titanium\TiMiniService.exeC:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exeC:\Program Files\Trend Micro\Titanium\TiResumeSrv.exeC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXEC:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exeC:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exeC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exeC:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exeC:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exeC:\Windows\SysWOW64\DllHost.exeC:\Windows\SysWOW64\DllHost.exeC:\Windows\system32\taskhost.exeC:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\system32\taskeng.exeC:\Program Files\Sony\VAIO Gate\VAIO Gate.exeC:\Program Files\Realtek\Audio\HDA\RAVBg64.exeC:\Program Files (x86)\Bluetooth Suite\BtvStack.exeC:\Program Files (x86)\Bluetooth Suite\AthBtTray.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Steam\Steam.exeC:\Program Files\Sandboxie\SbieCtrl.exeC:\Program Files\Aerofoil\Aerofoil.exeC:\Users\JK\AppData\Roaming\Dropbox\bin\Dropbox.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exeC:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exeC:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exeC:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exeC:\Program Files\AVAST Software\Avast\AvastUI.exeC:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\iTunes\iTunesHelper.exeC:\Program Files (x86)\Common Files\Java\Java Update\jusched.exeC:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exeC:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXEC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Sony\VAIO Smart Network\VSNService.exeC:\Windows\system32\SearchIndexer.exeC:\Program Files\Sony\VAIO Smart Network\VSNClient.exeC:\Windows\system32\svchost.exe -k bthsvcsC:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXEC:\Program Files\Windows Media Player\wmpnetwk.exeC:\Program Files (x86)\Common Files\Steam\SteamService.exeC:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exeC:\Windows\System32\svchost.exe -k LocalServicePeerNetC:\Program Files\Sony\VAIO Care\VCSystemTray.exec:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exeC:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exeC:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exeC:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exeC:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exeC:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exeC:\Program Files\Sony\VAIO Care\VCPerfService.exeC:\Program Files\Sony\VAIO Care\listener.exeC:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exeC:\Windows\System32\svchost.exe -k secsvcsC:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exeC:\Program Files\Sony\VAIO Care\VCService.exeC:\Program Files\Sony\VAIO Care\VCAgent.exeC:\Windows\System32\vds.exeC:\Program Files\Sony\VAIO Update\VUAgent.exeC:\Program Files\Sony\VAIO Care\VCAdmin.exeC:\Program Files\Sony\VAIO Improvement\vim.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files\Sony\VAIO Improvement\vim.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files\HitmanPro\hmpsched.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files\Sandboxie\SandboxieRpcSs.exeC:\Program Files\Sandboxie\SandboxieDcomLaunch.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files\Sandboxie\SandboxieCrypto.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exeC:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrolEx.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Windows\system32\NOTEPAD.EXEC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exeC:\Windows\system32\taskhost.exeC:\Windows\system32\taskeng.exeC:\Windows\system32\wbem\wmiprvse.exeC:\Windows\System32\cscript.exe.============== Pseudo HJT Report ===============.uDefault_Page_URL = hxxp://sony.msn.commWinlogon: Userinit = userinit.exe,BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllBHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1313\6.8.1072\TmIEPlg32.dllBHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dllBHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dllBHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dllBHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllBHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLLBHO: TmBpIeBHO Class: {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\7.0.1081\7.0.1081\TmBpIe32.dllBHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dllTB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} -TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dlluRun: [Google Update] "C:\Users\JK\AppData\Local\Google\Update\GoogleUpdate.exe" /cuRun: [GoogleChromeAutoLaunch_05267A1A13CB4BE6234C6C36C4380A35] "C:\Users\JK\AppData\Local\Google\Chrome\Application\chrome.exe" --no-startup-windowuRun: [steam] "C:\Program Files (x86)\Steam\steam.exe" -silentuRun: [sandboxieControl] "C:\Program Files\Sandboxie\SbieCtrl.exe"uRun: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressbootmRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRunmRun: [iAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exemRun: [uSB3MON] "C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"mRun: [iSBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"mRun: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exemRun: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exemRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /noguimRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottimemRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"StartupFolder: C:\Users\JK\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\ADOBEG~1.LNK - C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeStartupFolder: C:\Users\JK\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\JK\AppData\Roaming\Dropbox\bin\Dropbox.exeStartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Aerofoil.lnk - C:\Program Files\Aerofoil\Aerofoil.exeuPolicies-Explorer: NoDriveTypeAutoRun = dword:145mPolicies-Explorer: NoActiveDesktop = dword:1mPolicies-Explorer: NoActiveDesktopChanges = dword:1mPolicies-System: ConsentPromptBehaviorAdmin = dword:5mPolicies-System: ConsentPromptBehaviorUser = dword:3mPolicies-System: EnableUIADesktopToggle = dword:0IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~4\Office14\EXCEL.EXE/3000IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~4\Office14\ONBttnIE.dll/105IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dllIE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dllIE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dllIE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dllIE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204TCP: NameServer = 10.1.1.1TCP: Interfaces\{A2499BF0-F2FD-4313-94EF-D11278364F9C} : DHCPNameServer = 10.1.1.1TCP: Interfaces\{CCC3EC72-EB45-4B87-8C4C-1CE1054D2A27} : DHCPNameServer = 10.1.1.1Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLLHandler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\7.0.1081\7.0.1081\TmBpIe32.dllHandler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1313\6.8.1072\TmIEPlg32.dllHandler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dllAppInit_DLLs= prio32.dllSSODL: WebCheck - <orphaned>x64-BHO: TmIEPlugInBHO Class: {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1313\6.8.1072\TmIEPlg.dllx64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dllx64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dllx64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllx64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLLx64-BHO: TmBpIeBHO Class: {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\7.0.1081\7.0.1081\TmBpIe64.dllx64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dllx64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dllx64-Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SONYAPOx64-Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"x64-Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe"x64-Run: [synTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exex64-Run: [VizorHtmlDialog.exe] "C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe" "DEF" "EULA" "C:\Program Files\Trend Micro\Titanium\www\Installer.cmpt\resources\preinstall_01_welcome_trial.html" "DEF" "DEF" "DEF"x64-Run: [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"x64-Run: [Trend Micro Titanium] "C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe" -ReFlush "none" "none"x64-Run: [Logitech Download Assistant] C:\Windows\System32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetchx64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dllx64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dllx64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLLx64-Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\7.0.1081\7.0.1081\TmBpIe64.dllx64-Handler: tmpx - {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\2.0.1313\6.8.1072\TmIEPlg.dllx64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>x64-SSODL: WebCheck - <orphaned>.============= SERVICES / DRIVERS ===============.R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-1 65336]R0 iusb3hcs;Intel® USB 3.0 Host Controller Switch Driver;C:\Windows\System32\drivers\iusb3hcs.sys [2012-2-28 16152]R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-5-30 55856]R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-7-6 1025808]R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-7-6 377920]R1 tmevtmgr;tmevtmgr;C:\Windows\System32\drivers\tmevtmgr.sys [2012-5-30 70928]R2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [2011-9-1 169624]R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2012-4-16 235520]R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-7-6 33400]R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-7-6 80816]R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Bluetooth Suite\AdminService.exe [2012-1-20 106144]R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-19 130384]R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-19 138576]R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2012-1-4 822624]R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-5-29 13592]R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-5-29 2429544]R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-2-3 628448]R2 Intel® ME Service;Intel® ME Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [2012-5-29 121344]R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-5-29 161560]R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2012-11-3 418376]R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-11-3 701512]R2 NOBU;Norton Online Backup;C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2011-11-3 4700824]R2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [2012-2-22 473960]R2 SampleCollector;VAIO Care Performance Service;C:\Program Files\Sony\VAIO Care\VCPerfService.exe [2011-12-1 260768]R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2011-10-1 508776]R2 TiMiniService;TiMiniService;C:\Program Files\Trend Micro\Titanium\TiMiniService.exe [2011-9-24 247072]R2 uCamMonitor;CamMonitor;C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2012-5-30 105024]R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-5-29 363800]R2 VSNService;VSNService;C:\Program Files\Sony\VAIO Smart Network\VSNService.exe [2012-5-30 978056]R3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;C:\Windows\System32\drivers\ArcSoftKsUFilter.sys [2012-5-30 19968]R3 AthBTPort;Atheros Virtual Bluetooth Class;C:\Windows\System32\drivers\btath_flt.sys [2012-1-20 36000]R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2012-4-16 95248]R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\drivers\btath_a2dp.sys [2012-1-20 339616]R3 btath_avdt;Atheros Bluetooth AVDT Service;C:\Windows\System32\drivers\btath_avdt.sys [2012-1-20 110752]R3 BTATH_BUS;Atheros Bluetooth Bus;C:\Windows\System32\drivers\btath_bus.sys [2012-1-20 30368]R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\drivers\btath_hcrp.sys [2012-1-20 167584]R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\drivers\btath_lwflt.sys [2012-1-20 68256]R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\drivers\btath_rcp.sys [2012-1-20 280992]R3 BTATH_VDP;Bluetooth VDP Driver;C:\Windows\System32\drivers\btath_vdp.sys [2012-1-20 421664]R3 BtFilter;BtFilter;C:\Windows\System32\drivers\btfilter.sys [2012-1-20 550560]R3 iusb3hub;Intel® USB 3.0 Hub Driver;C:\Windows\System32\drivers\iusb3hub.sys [2012-2-28 356120]R3 iusb3xhc;Intel® USB 3.0 eXtensible Host Controller Driver;C:\Windows\System32\drivers\iusb3xhc.sys [2012-2-28 787736]R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-11-3 25928]R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-2-10 565352]R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2012-12-16 202632]R3 SFEP;Sony Firmware Extension Parser;C:\Windows\System32\drivers\SFEP.sys [2012-1-16 14336]R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2011-10-1 764264]R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2011-10-1 268648]R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2011-10-1 25960]R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2011-10-1 22376]R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2011-10-1 219496]R3 VCService;VCService;C:\Program Files\Sony\VAIO Care\VCService.exe [2012-1-21 54432]S2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-3-9 45248]S3 Amsp;Trend Micro Solution Platform;C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe [2012-5-30 275912]S3 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-3-1 178624]S3 BBSvc;Bing Bar Update Service;C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-3-2 183560]S3 DCDhcpService;DCDhcpService;C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [2012-5-30 112256]S3 e1yexpress;Intel® Gigabit Network Connections Driver;C:\Windows\System32\drivers\e1y60x64.sys [2009-6-11 281088]S3 Revoflt;Revoflt;C:\Windows\System32\drivers\revoflt.sys [2013-4-30 31800]S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2012-5-29 340072]S3 SOHCImp;VAIO Content Importer;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2012-1-7 138392]S3 SOHDs;VAIO Device Searcher;C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe [2012-1-7 74904]S3 SpfService;VAIO Entertainment Common Service;C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe [2011-12-2 289952]S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-21 59392]S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-21 31232]S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]S3 VAIO Power Management;VAIO Power Management;C:\Program Files\Sony\VAIO Power Management\SPMService.exe [2012-5-29 535688]S3 VCFw;VAIO Content Folder Watcher;C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2011-12-30 960160]S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2011-12-22 550128]S3 VcmINSMgr;VAIO Content Metadata Intelligent Network Service Manager;C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe [2011-12-22 382720]S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe [2011-8-27 101600].=============== Created Last 30 ================.2013-05-20 10:55:25 -------- d-----w- C:\Users\JK\AppData\Roaming\WinPatrol2013-05-20 10:55:03 -------- d-----w- C:\ProgramData\InstallMate2013-05-20 10:55:03 -------- d-----w- C:\Program Files (x86)\BillP Studios2013-05-20 08:27:14 12872 ----a-w- C:\Windows\System32\bootdelete.exe2013-05-20 08:10:07 -------- d-----w- C:\Program Files\HitmanPro2013-05-20 08:09:29 -------- d-----w- C:\ProgramData\HitmanPro2013-05-19 11:16:50 76232 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4E532360-C896-4453-B412-9A06ADC94777}\offreg.dll2013-05-19 11:11:49 8199504 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll2013-05-19 11:11:45 9460464 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{4E532360-C896-4453-B412-9A06ADC94777}\mpengine.dll2013-05-19 08:33:35 -------- d-----r- C:\Users\JK\Dropbox2013-05-19 08:31:51 -------- d-----w- C:\Users\JK\AppData\Roaming\Dropbox2013-05-18 11:35:21 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb2013-05-18 11:35:21 2382848 ----a-w- C:\Windows\System32\mshtml.tlb2013-05-18 08:36:00 983400 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys2013-05-18 08:36:00 265064 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys2013-05-18 08:36:00 144384 ----a-w- C:\Windows\System32\cdd.dll2013-05-18 08:35:36 1930752 ----a-w- C:\Windows\System32\authui.dll2013-05-18 08:35:30 1796096 ----a-w- C:\Windows\SysWow64\authui.dll2013-05-18 08:35:30 111448 ----a-w- C:\Windows\System32\consent.exe2013-05-18 08:35:28 70144 ----a-w- C:\Windows\System32\appinfo.dll2013-05-18 08:34:37 48640 ----a-w- C:\Windows\System32\wwanprotdim.dll2013-05-18 08:34:37 230400 ----a-w- C:\Windows\System32\wwansvc.dll2013-05-18 08:34:36 3153920 ----a-w- C:\Windows\System32\win32k.sys2013-05-18 04:54:58 -------- d-----w- C:\Users\JK\AppData\Roaming\Python-Eggs2013-05-08 06:08:02 -------- d-----w- C:\Users\JK\AppData\Local\Game Dev Tycoon2013-05-04 05:09:34 -------- d-----w- C:\Users\JK\AppData\Local\Humanbalance2013-05-04 05:09:30 -------- d-----w- C:\Program Files (x86)\GraphicsGale FreeEdition2013-04-30 09:22:55 -------- d-----w- C:\Users\JK\AppData\Roaming\QuickScan2013-04-30 07:42:08 0 ----a-w- C:\Windows\SysWow64\sho1C20.tmp2013-04-30 06:35:50 -------- d-----w- C:\Users\JK\AppData\Local\VS Revo Group2013-04-30 06:35:30 -------- d-----w- C:\ProgramData\VS Revo Group2013-04-30 06:35:29 31800 ----a-w- C:\Windows\System32\drivers\revoflt.sys2013-04-30 06:35:26 -------- d-----w- C:\Program Files\VS Revo Group2013-04-27 06:12:57 -------- d-----w- C:\Users\JK\AppData\Roaming\Lionhead Studios2013-04-27 06:11:01 -------- d-----w- C:\Windows\SysWow64\xlive2013-04-27 06:10:42 -------- d-----w- C:\Program Files (x86)\Microsoft Games for Windows - LIVE2013-04-25 22:26:43 95648 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll2013-04-24 06:35:22 1656680 ----a-w- C:\Windows\System32\drivers\ntfs.sys2013-04-23 08:01:41 -------- d-----w- C:\Users\JK\AppData\Roaming\.technic.==================== Find3M ====================.2013-05-15 07:20:34 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl2013-05-15 07:20:34 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe2013-05-01 16:06:08 278800 ------w- C:\Windows\System32\MpSigStub.exe2013-04-13 05:49:23 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll2013-04-13 05:49:19 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll2013-04-13 05:49:19 308736 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll2013-04-13 05:49:19 111104 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll2013-04-13 04:45:16 474624 ----a-w- C:\Windows\apppatch\AcSpecfc.dll2013-04-13 04:45:15 2176512 ----a-w- C:\Windows\apppatch\AcGenral.dll2013-04-05 01:08:44 2312704 ----a-w- C:\Windows\System32\jscript9.dll2013-04-05 01:00:30 1392128 ----a-w- C:\Windows\System32\wininet.dll2013-04-05 00:59:24 1494528 ----a-w- C:\Windows\System32\inetcpl.cpl2013-04-05 00:56:16 173056 ----a-w- C:\Windows\System32\ieUnatt.exe2013-04-05 00:55:47 599040 ----a-w- C:\Windows\System32\vbscript.dll2013-04-04 22:11:34 1800704 ----a-w- C:\Windows\SysWow64\jscript9.dll2013-04-04 22:02:59 1427968 ----a-w- C:\Windows\SysWow64\inetcpl.cpl2013-04-04 22:02:17 1129472 ----a-w- C:\Windows\SysWow64\wininet.dll2013-04-04 21:58:51 142848 ----a-w- C:\Windows\SysWow64\ieUnatt.exe2013-04-04 21:57:45 420864 ----a-w- C:\Windows\SysWow64\vbscript.dll2013-04-04 04:50:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys2013-03-23 01:07:10 108448 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll2013-03-23 01:07:01 1085344 ----a-w- C:\Windows\System32\npDeployJava1.dll2013-03-23 01:07:00 963488 ----a-w- C:\Windows\System32\deployJava1.dll2013-03-23 00:59:03 861088 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll2013-03-23 00:59:03 782240 ----a-w- C:\Windows\SysWow64\deployJava1.dll2013-03-19 06:04:06 5550424 ----a-w- C:\Windows\System32\ntoskrnl.exe2013-03-19 05:46:56 43520 ----a-w- C:\Windows\System32\csrsrv.dll2013-03-19 05:04:13 3968856 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe2013-03-19 05:04:10 3913560 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe2013-03-19 04:47:50 6656 ----a-w- C:\Windows\SysWow64\apisetschema.dll2013-03-19 03:06:33 112640 ----a-w- C:\Windows\System32\smss.exe2013-03-06 23:33:21 70992 ----a-w- C:\Windows\System32\drivers\aswRdr2.sys2013-03-06 23:33:21 65336 ----a-w- C:\Windows\System32\drivers\aswRvrt.sys2013-03-06 23:33:21 178624 ----a-w- C:\Windows\System32\drivers\aswVmm.sys2013-03-06 23:33:21 1025808 ----a-w- C:\Windows\System32\drivers\aswSnx.sys2013-03-06 23:33:20 80816 ----a-w- C:\Windows\System32\drivers\aswMonFlt.sys2013-03-06 23:32:51 41664 ----a-w- C:\Windows\avastSS.scr2013-02-20 07:29:24 111928 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe.============= FINISH: 21:13:57.10 ===============AutoKMS.log Link to post Share on other sites More sharing options...
D-FRED-BROWN Posted May 22, 2013 ID:682678 Share Posted May 22, 2013 KMSEmulator is a program that was likely installed on your computer by someone who was trying to pirate some form of commercial software. Microsoft Office, for example, is a pretty common one.KMSEmulator itself probably isn't a virus or security threat, but many antivirus companies flag such cracks/keygens as "potentially unwanted software" or "hacktools". If you remove the scheduled tasks and delete any .exe files related to KMSEmulator, you should be fine, though it is up to you. Alternatively, if you suspect your computer has been infected, I can assist you in cleaning it. Let me know how you'd like to proceed. -DFB Link to post Share on other sites More sharing options...
Maurice Naggar Posted May 25, 2013 ID:683681 Share Posted May 25, 2013 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts