hi, im very happy that you want to help me.
here are the logs:
SysProt AntiRootkit v1.0.1.0
by swatkat
*************************************************************************** ***************
*************************************************************************** ***************
No Hidden Processes found
*************************************************************************** ***************
*************************************************************************** ***************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\spmo.sys
Service Name: ---
Module Base: 88A98000
Module End: 88B8B000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys
Service Name: ---
Module Base: 81FC3000
Module End: 81FCE000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: ---
Module Base: 81FCE000
Module End: 81FD7000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_dumpfve.sys
Service Name: ---
Module Base: 81FD7000
Module End: 81FE8000
Hidden: Yes
*************************************************************************** ***************
*************************************************************************** ***************
No SSDT Hooks found
*************************************************************************** ***************
*************************************************************************** ***************
No Kernel Hooks found
*************************************************************************** ***************
*************************************************************************** ***************
No IRP Hooks found
*************************************************************************** ***************
*************************************************************************** ***************
Ports:
Local Address: CHASE:49229
Remote Address: 74.125.13.89:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49228
Remote Address: FK-IN-F102.1E100.NET:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49227
Remote Address: EY-IN-F137.1E100.NET:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49226
Remote Address: FX-IN-F138.1E100.NET:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49225
Remote Address: EY-IN-F103.1E100.NET:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49224
Remote Address: EY-IN-F103.1E100.NET:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49223
Remote Address: FK-IN-F102.1E100.NET:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49222
Remote Address: FK-IN-F102.1E100.NET:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49221
Remote Address: A92-123-148-20.DEPLOY.AKAMAITECHNOLOGIES.COM:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49220
Remote Address: BW-IN-F139.1E100.NET:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49219
Remote Address: BW-IN-F139.1E100.NET:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49218
Remote Address: A92-122-188-59.DEPLOY.AKAMAITECHNOLOGIES.COM:HTTP
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: CHASE:49213
Remote Address: LOCALHOST:49212
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49212
Remote Address: LOCALHOST:49213
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49211
Remote Address: LOCALHOST:49210
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49210
Remote Address: LOCALHOST:49211
Type: TCP
Process: 1728 (PID)
State: ESTABLISHED
Local Address: CHASE:49156
Remote Address: 0.0.0.0:0
Type: TCP
Process: 520 (PID)
State: LISTENING
Local Address: CHASE:49155
Remote Address: 0.0.0.0:0
Type: TCP
Process: 512 (PID)
State: LISTENING
Local Address: CHASE:49154
Remote Address: 0.0.0.0:0
Type: TCP
Process: 964 (PID)
State: LISTENING
Local Address: CHASE:49153
Remote Address: 0.0.0.0:0
Type: TCP
Process: 888 (PID)
State: LISTENING
Local Address: CHASE:49152
Remote Address: 0.0.0.0:0
Type: TCP
Process: 448 (PID)
State: LISTENING
Local Address: CHASE:10243
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: CHASE:WSD
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: CHASE:ICSLAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: CHASE:RTSP
Remote Address: 0.0.0.0:0
Type: TCP
Process: 3240 (PID)
State: LISTENING
Local Address: CHASE:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: 4 (PID)
State: LISTENING
Local Address: CHASE:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: 788 (PID)
State: LISTENING
Local Address: CHASE:63703
Remote Address: NA
Type: UDP
Process: 3124 (PID)
State: NA
Local Address: CHASE:SSDP
Remote Address: NA
Type: UDP
Process: 3124 (PID)
State: NA
Local Address: CHASE:138
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: CHASE:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: 4 (PID)
State: NA
Local Address: CHASE:63704
Remote Address: NA
Type: UDP
Process: 3124 (PID)
State: NA
Local Address: CHASE:49152
Remote Address: NA
Type: UDP
Process: 460 (PID)
State: NA
Local Address: CHASE:SSDP
Remote Address: NA
Type: UDP
Process: 3124 (PID)
State: NA
Local Address: CHASE:50977
Remote Address: NA
Type: UDP
Process: 1132 (PID)
State: NA
Local Address: CHASE:50975
Remote Address: NA
Type: UDP
Process: 3124 (PID)
State: NA
Local Address: CHASE:LLMNR
Remote Address: NA
Type: UDP
Process: 1284 (PID)
State: NA
Local Address: CHASE:5005
Remote Address: NA
Type: UDP
Process: 3240 (PID)
State: NA
Local Address: CHASE:5004
Remote Address: NA
Type: UDP
Process: 3240 (PID)
State: NA
Local Address: CHASE:IPSEC-MSFT
Remote Address: NA
Type: UDP
Process: 964 (PID)
State: NA
Local Address: CHASE:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 3124 (PID)
State: NA
Local Address: CHASE:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1132 (PID)
State: NA
Local Address: CHASE:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 3124 (PID)
State: NA
Local Address: CHASE:WS-DISCOVERY
Remote Address: NA
Type: UDP
Process: 1132 (PID)
State: NA
Local Address: CHASE:500
Remote Address: NA
Type: UDP
Process: 964 (PID)
State: NA
*************************************************************************** ***************
*************************************************************************** ***************
Hidden files/folders:
Object: C:\System Volume Information\ISwift3.dat
Status: Access denied
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\SPP
Status: Access denied
Object: C:\System Volume Information\Syscache.hve
Status: Access denied
Object: C:\System Volume Information\Syscache.hve.LOG1
Status: Access denied
Object: C:\System Volume Information\Syscache.hve.LOG2
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\System Volume Information\Windows Backup
Status: Access denied
Object: C:\System Volume Information\WindowsImageBackup\SPPMetadataCache
Status: Access denied
Object: C:\System Volume Information\WindowsImageBackup
Status: Access denied
Object: C:\System Volume Information\{1b956e5f-cedf-11de-8abd-001a4f9d97fa}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{7472e7b1-cf9d-11de-adba-001a4f9d97fa}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{aa5793b3-ceeb-11de-a7a6-001a4f9d97fa}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{acca5696-cfa0-11de-b9fe-001a4f9d97fa}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\Windows\CSC\v2.0.6\namespace
Status: Access denied
Object: C:\Windows\CSC\v2.0.6\pq
Status: Access denied
Object: C:\Windows\CSC\v2.0.6\sm
Status: Access denied
Object: C:\Windows\CSC\v2.0.6\temp
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession7.etl
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl
Status: Access denied
and the other one attached, as desired
Greetings, Snajper