ComboFix.txt:
ComboFix 14-10-24.01 - Dandy 10/25/2014 8: 33.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1256.981.1033.18.6058.4295 [GMT 3.5: 30]
Çalışan: c: \ users \ Dandy \ Desktop \ ComboFix.exe
AV: Kaspersky Internet Security * Devre dışı / Güncellenmiş * {C3113FBF-4BCB-4461-D78D-6EDFEC9593E5}
FW: Kaspersky Internet Security * Devre Dışı * {FB2ABE9A-01A4-4539-FCD2-C7EA1246D49E}
SP: Kaspersky Internet Security * Devre Dışı / Güncelleme * {7870DE5B-6DF1-4BEF-ED3D-55AD9712D958}
SP: Windows Defender * Devre Dışı / Eski * * D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((((((((((Diğer (Silme)))))))) ))))))))))))))))))))))))))))))))))))))))
.
.
c: \ programdata \ Roaming
c: \ windows \ wininit.ini
C: \ WINDOWS \ XSxS
.
.
(((((((((((((((((((((((((((((((((((((((Sürücüler / Servisler)))))))) )))))))))))))))))))))))))))))))))))))))))
.
.
------- \ Service_DCService.exe
.
.
(((((((((((((((((((((((((2014. 2014-09-25 ile 2014-10-25 arasında oluşturulan dosyalar)))))))))))) ))))))))))))))))))))
.
.
2014-10-25 05:12. 2014-10-25 05:12 -------- d ----- w- c: \ users \ UpdatusUser \ AppData \ Local \ temp
2014-10-25 05:12. 2014-10-25 05:12 -------- d ----- w- c: \ users \ Default \ AppData \ Local \ temp
2014-10-25 05:01. 2014-10-25 05:01 -------- d ----- w- c: \ users \ Dandy \ AppData \ Local \ CrashDumps
2014-10-24 07:42. 2014-10-24 07:57 -------- d ----- w- c: \ programdata \ Malwarebytes 'Kötü Amaçlı Yazılımdan Koruma (taşınabilir)
2014-10-24 07:32. 2014-10-24 07:32 75888 ---- a-w- c: \ programdata \ Microsoft \ Windows Defender \ Tanım Güncellemeleri \ {083E18CE-489B-4E24-9DFC-12DDA415D8DB} \ offreg.dll
2014-10-24 07:24. 2014-10-24 07:24 34808 ---- a-w- c: \ windows \ system32 \ drivers \ TrueSight.sys
2014-10-24 07:23. 2014-10-24 07:24 -------- d ----- w- c: \ programdata \ RogueKiller
2014-10-22 15:49. 2014-10-25 04:58 129752 ---- a-w- c: \ windows \ system32 \ drivers \ MBAMSwissArmy.sys
2014-10-22 15:49. 2014-10-24 07:24 92888 ---- a-w- c: \ windows \ system32 \ drivers \ mbamchameleon.sys
2014-10-22 15:49. 2014-10-22 15:49 -------- d ----- w- c: \ program dosyaları (x86) \ Malwarebytes Anti-Malware
2014-10-22 15:49. 2014-10-22 15:49 -------- d ----- w- c: \ programdata \ Malwarebytes
2014-10-22 15:49. 2014-10-01 07:41 63704 ---- a-w- c: \ windows \ system32 \ drivers \ mwac.sys
2014-10-22 15:49. 2014-10-01 07:41 25816 ---- a-w- c: \ windows \ system32 \ drivers \ mbam.sys
2014-10-22 14:31. 2014-10-22 14:31 -------- d ----- w- c: \ program dosyaları (x86) \ Mozilla Bakım Servisi
2014-10-20 22:31. 2014-05-14 16:23 44512 ---- a-w- c: \ windows \ system32 \ wups2.dll
2014-10-20 22:31. 2014-05-14 16:23 58336 ---- a-w- c: \ windows \ system32 \ wuauclt.exe
2014-10-20 22:31. 2014-05-14 16:23 2477536 ---- a-w- c: \ windows \ system32 \ wuaueng.dll
2014-10-20 22:31. 2014-05-14 16:21 2620928 ---- a-w- c: \ windows \ system32 \ WindowsCodecs.dll
2014-10-20 22:31. 2014-05-14 16:23 38880 ---- a-w- c: \ windows \ system32 \ wups.dll
2014-10-20 22:31. 2014-05-14 16:23 36320 ---- a-w- c: \ windows \ SysWow64 \ wups.dll
2014-10-20 22:31. 2014-05-14 16:23 700384 ---- a-w- c: \ windows \ system32 \ wuapi.dll
2014-10-20 22:31. 2014-05-14 16:23 581600 ---- a-w- c: \ windows \ SysWow64 \ wuapi.dll
2014-10-20 22:31. 2014-05-14 16:20 97792 ---- a-w- c: \ windows \ system32 \ wudriver.dll
2014-10-20 22:31. 2014-05-14 16:17 92672 ---- a-w- c: \ windows \ SysWow64 \ wudriver.dll
2014-10-20 22:30. 2014-05-14 05:53 198600 ---- a-w- c: \ windows \ system32 \ wuwebv.dll
2014-10-20 22:30. 2014-05-14 05:53 179656 ---- a-w- c: \ windows \ SysWow64 \ wuwebv.dll
2014-10-20 22:30. 2014-05-14 05:50 36864 ---- a-w- c: \ windows \ system32 \ wuapp.exe
2014-10-20 22:30. 2014-05-14 05:47 33792 ---- a-w- c: \ windows \ SysWow64 \ wuapp.exe
2014-10-20 14:41. 2014-10-22 16:58 -------- d ----- w- c: \ program dosyaları (x86) \ Ask.com
2014-10-20 14:15. 2014-10-20 14:15 -------- d ----- w- c: \ users \ Dandy \ AppData \ Roaming \ smileyswelove
2014-10-20 13:58. 2014-04-25 11:19 20312 ---- a-w- c: \ windows \ system32 \ roboot64.exe
2014-10-20 13:58. 2014-10-22 16:58 -------- d ----- w- c: \ users \ Dandy \ AppData \ Roaming \ systweak
2014-10-18 13:09. 2014-10-22 16:58 -------- d ----- w- c: \ program dosyaları (x86) \ Internet Download Manager
2014-10-18 09:44. 2014-10-22 16:58 -------- d ----- w- c: \ program dosyaları (x86) \ globalUpdate
2014-10-18 09:44. 2014-10-18 09:44 -------- d ----- w- c: \ users \ Dandy \ AppData \ Local \ globalUpdate
2014-10-18 04:27. 2014-10-18 10:24 -------- d ----- w- c: \ program dosyaları (x86) \ Ortak Dosyalar \ Symantec Shared
2014-10-16 20:57. 2014-10-16 20:57 -------- d ----- w- c: \ program dosyaları \ Elantech
2014-10-16 20:55. 2014-10-16 20:55 5047080 ---- a-w- c: \ windows \ system32 \ ETDUI.cpl
2014-10-16 20:30. 2014-10-16 20:30 -------- d ----- w- c: \ users \ Dandy \ AppData \ Roaming \ NVIDIA
2014-10-16 20:26. 2010-11-12 22:23 252712 ---- a-w- c: \ windows \ ETDUninst.dll
2014-10-16 20:19. 2014-10-16 20:19 -------- d ----- w- c: \ users \ Dandy \ AppData \ Local \ Installer
2014-10-16 20:09. 2014-10-16 20:09 -------- d ----- w- c: \ users \ Dandy \ AppData \ Roaming \ BandExtend
2014-10-16 19:46. 2014-10-16 19:46 -------- d ----- w- c: \ users \ Dandy \ AppData \ Local \ Cool_Mirage
2014-10-16 19:43. 2014-10-16 19:43 -------- d ----- w- c: \ users \ Dandy \ AppData \ Roaming \ WebExtend
2014-10-16 18:57. 2014-10-16 18:57 -------- d ----- w- c: \ users \ Dandy \ AppData \ Local \ CrashRpt
2014-10-16 18:52. 2014-10-16 21:08 -------- d ----- w- c: \ users \ Dandy \ AppData \ Local \ calibre-cache
2014-10-16 18:50. 2014-10-16 20:27 -------- d ----- w- c: \ users \ Dandy \ AppData \ Roaming \ calibre
2014-10-16 18:36. 2014-10-16 18:36 -------- d ----- w- c: \ users \ Dandy \ AppData \ Roaming \ DawningSoft
2014-10-16 18:36. 1997-12-19 10:56 68096 ---- a-w- c: \ windows \ SysWow64 \ Itcc.dll
2014-10-15 08:55. 2014-10-01 06:19 180136 ---- a-w- c: \ windows \ system32 \ drivers \ idmwfp.sys
2014-10-14 03:58. 2014-10-14 03:58 -------- d ----- w- c: \ programdata \ Kaspersky Lab Kurulum Dosyaları
2014-10-14 00:04. 2014-09-14 22:38 11578928 ---- a-w- c: \ programdata \ Microsoft \ Windows Defender \ Tanım Güncellemeleri \ {083E18CE-489B-4E24-9DFC-12DDA415D8DB} \ mpengine.dll
2014-09-27 06:17. 2014-09-27 06:17 -------- d ----- w- c: \ users \ Dandy \ yf
2014-09-27 04:29. 2014-09-27 04:29 -------- d ----- w- c: \ users \ Dandy \ AppData \ Local \ Özgürlüğünüz
.
.
.
[ ))))))))))))))))))))))))))))))))))))))))))))
.
2014-10-16 21:06. 2011-08-23 09:54 345600 ---- a-w- c: \ windows \ SetLCDStretchMode.exe
2014-10-16 21:06. 2011-08-23 09:54 407040 ---- a-w- c: \ windows \ HotfixChecker.exe
2014-09-15 05:36. 2010-11-21 03:27 278152 ------ w- c: \ windows \ system32 \ MpSigStub.exe
2014-09-05 02:35. 2010-06-24 02:33 23256 ---- a-w- c: \ programdata \ Microsoft \ IdentityCRL \ production \ ppcrlconfig600.dll
2012-09-05 10:30. 2012-09-05 10:30 2174976 ---- a-w- c: \ program dosyaları (x86) \ Common Files \ atimpenc.dll
.
.
[ ))))))))))))))))))))))))))))))))))))))))
.
.
* Not * boş girişler ve yasal varsayılan girişler gösterilmez
REGEDIT4
.
[HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"Sidebar" = "c: \ program files \ Windows Sidebar \ sidebar.exe" [2010-11-21 1475584]
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Wow6432Node \ Microsoft \ Windows \ CurrentVersion \ Run]
"SunJavaUpdateSched" = "c: \ program dosyaları (x86) \ Ortak Dosyalar \ Java \ Java Güncellemesi \ jusched.exe" [2012-07-03 252848]
"Adobe ARM" = "c: \ program dosyaları (x86) \ Ortak Dosyalar \ Adobe \ ARM \ 1.0 \ AdobeARM.exe" [2013-11-21 959904]
"AVP" = "c: \ program dosyaları (x86) \ Kaspersky Lab \ Kaspersky Internet Security 2013 \ avp.exe" [2013-10-11 356128]
"ApnUpdater" = "c: \ program dosyaları (x86) \ Ask.com \ Updater \ Updater.exe" [2014-01-28 1721776]
.
[HKEY_USERS \ .DEFAULT \ Software \ Microsoft \ Windows \ CurrentVersion \ Run]
"Sidebar" = "c: \ program files \ Windows Sidebar \ sidebar.exe" [2010-11-21 1475584]
.
c: \ programdata \ Microsoft \ Windows \ Başlat Menüsü \ Programlar \ Startup \
Canon LBP2900 Durum Penceresi.lnk - c: \ windows \ System32 \ spool \ drivers \ x64 \ 3 \ CNAB4LAD.EXE [2012-11-5 60384]
WD Quick View.lnk - c: \ program dosyaları \ Western Digital \ WD SmartWare \ WDDMStatus.exe [2011-8-1 4221840]
.
[HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Windows \ CurrentVersion \ Policies \ sistemi]
"ConsentPromptBehaviorAdmin" = 0 (0x0)
"ConsentPromptBehaviorUser" = 3 (0x3)
"EnableLUA" = 0 (0x0)
"EnableUIADesktopToggle" = 0 (0x0)
"PromptOnSecureDesktop" = 0 (0x0)
.
[HKEY_LOCAL_MACHINE \ software \ wow6432node \ microsoft \ windows nt \ currentversion \ windows]
"LoadAppInit_DLLs" = 1 (0x1)
"AppInit_DLLs" = C: \ WINDOWS \ SysWOW64 \ nvinit.dll
.
[HKEY_LOCAL_MACHINE \ software \ wow6432node \ microsoft \ windows nt \ currentversion \ drivers32]
"Mixer5" = wdmaud.drv
.
[HKEY_LOCAL_MACHINE \ yazılım \ microsoft \ güvenlik merkezi \ Monitoring \ KasperskyAntiVirus]
"DisableMonitoring" = dword: 00000001
.
R2 clr_optimization_v4.0.30319_64; Microsoft .NET Framework NGEN v4.0.30319_X64; c: \ windows \ Microsoft.NET \ Framework64 \ v4.0.30319 \ mscorsvw.exe; c: \ windows \ Microsoft.NET \ Framework64 \ v4.0.30319 \ mscorsvw.exe [x]
R2 MBAMService; MBAMService; c: \ program dosyaları (x86) \ Malwarebytes Anti-Malware \ mbamservice.exe; c: \ program dosyaları (x86) \ Malwarebytes Anti-Malware \ mbamservice.exe [x]
R2 SkypeUpdate; Skype Güncelleyici; c: \ program dosyaları (x86) \ Skype \ Updater \ Updater.exe; c: \ program dosyaları (x86) \ Skype \ Updater \ Updater.exe [x]
R3 AMPPALP; Intel (R) Centrino (R) Bluetooth 3.0 + Yüksek Hızlı Protokol; c: \ windows \ system32 \ DRIVERS \ amppal.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ amppal.sys [x]
R3 BBUpdate; BBUpdate; c: \ program dosyaları (x86) \ Microsoft \ BingBar \ 7.3.132.0 \ SeaPort.exe; c: \ program dosyaları (x86) \ Microsoft \ BingBar \ 7.3.132.0 \ SeaPort.exe [x]
R3 btmaudio; Intel Bluetooth Ses Hizmeti; c: \ windows \ system32 \ drivers \ btmaud.sys; c: \ windows \ SYSNATIVE \ drivers \ btmaud.sys [x]
R3 dg_ssudbus; SAMSUNG Mobil USB Kompozit Aygıt Sürücüsü (DEVGURU Ver.); C: \ windows \ system32 \ DRIVERS \ ssudbus.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ ssudbus.sys [x]
R3 ew_hwusbdev; Huawei MobileBroadband USB PNP Cihazı; c: \ windows \ system32 \ DRIVERS \ ew_hwusbdev.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ ew_hwusbdev.sys [x]
R3 ewusbnet; HUAWEI USB-NDIS miniport; c: \ windows \ system32 \ DRIVERS \ ewusbnet.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ ewusbnet.sys [x]
R3 intaud_WaveExtensible; Intel WiDi Ses Aygıtı; c: \ windows \ system32 \ drivers \ intelaud.sys; c: \ windows \ SYSNATIVE \ drivers \ intelaud.sys [x]
R3 MBAMWebAccessControl; MBAMWebAccessControl; c: \ windows \ system32 \ drivers \ mwac.sys; c: \ windows \ SYSNATIVE \ drivers \ mwac.sys [x]
R3 MyWiFiDHCPDNS; Kablosuz PAN DHCP Sunucusu; c: \ program dosyaları \ Intel \ WiFi \ bin \ PanDhcpDns.exe; c: \ program dosyaları \ Intel \ WiFi \ bin \ PanDhcpDns.exe [x]
R3 RTL8167; Realtek 8167 NT Sürücüsü; c: \ windows \ system32 \ DRIVERS \ Rt64win7.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ Rt64win7.sys [x]
R3 Samsung UPD Hizmeti; Samsung UPD Hizmeti; c: \ windows \ System32 \ SUPDSvc.exe; c: \ windows \ SYSNATIVE \ SUPDSvc.exe [x]
R3 ssudmdm; SAMSUNG Mobil USB Modem Sürücüleri (DEVGURU Ver.); C: \ windows \ system32 \ DRIVERS \ ssudmdm.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ ssudmdm.sys [x]
R3 TsUsbFlt; TsUsbFlt; c: \ windows \ system32 \ drivers \ tsusbflt.sys; c: \ windows \ SYSNATIVE \ drivers \ tsusbflt.sys [x]
R3 TsUsbGD; Uzak Masaüstü Genel USB Aygıtı; c: \ windows \ system32 \ drivers \ TsUsbGD.sys; c: \ windows \ SYSNATIVE \ drivers \ TsUsbGD.sys [x]
R3 TurboBoost; Intel (R) Turbo Boost Teknoloji İzleyicisi 2.0; c: \ program dosyaları \ Intel \ TurboBoost \ TurboBoost.exe; c: \ program dosyaları \ Intel \ TurboBoost \ TurboBoost.exe [x]
R3 usbrndis6; USB RNDIS6 Adaptörü; c: \ windows \ system32 \ DRIVERS \ usb80236.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ usb80236.sys [x]
R3 WatAdminSvc; Windows Etkinleştirme Teknolojileri Hizmeti; c: \ windows \ system32 \ Wat \ WatAdminSvc.exe; c: \ windows \ SYSNATIVE \ Wat \ WatAdminSvc.exe [x]
R3 WDC_SAM; WD SCSI Geçiş Sürücüsü; c: \ windows \ system32 \ DRIVERS \ wdcsam64.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ wdcsam64.sys [x]
R4 MBAMScheduler; MBAMScheduler; c: \ program dosyaları (x86) \ Malwarebytes Anti-Malware \ mbamscheduler.exe; c: \ program dosyaları (x86) \ Malwarebytes Anti-Malware \ mbamscheduler.exe [x]
R4 wlcrasvc; Windows Live Mesh uzaktan bağlantı hizmeti; c: \ program dosyaları \ Windows Live \ Mesh \ wlcrasvc.exe; c: \ program dosyaları \ Windows Live \ Mesh \ wlcrasvc.exe [x]
S0 nvpciflt; nvpciflt; c: \ windows \ system32 \ DRIVERS \ nvpciflt.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ nvpciflt.sys [x]
S1 KLIM6; Kaspersky Anti-Virüs NDIS 6 Filtresi; c: \ windows \ system32 \ DRIVERS \ klim6.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ klim6.sys [x]
S1 kltdi; kltdi; c: \ windows \ system32 \ DRIVERS \ kltdi.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ kltdi.sys [x]
S1 kneps; kneps; c: \ windows \ system32 \ DRIVERS \ kneps.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ kneps.sys [x]
S1 SABI; Windows 7 için SAMSUNG Çekirdek Sürücüsü; c: \ windows \ system32 \ Sürücüler \ SABI.sys; c: \ windows \ SYSNATIVE \ Sürücüler \ SABI.sys [x]
S2 AMPPALR3; Intel® Centrino® Bluetooth 3.0 + Yüksek Hızlı Hizmet; c: \ program dosyaları \ Intel \ BluetoothHS \ BTHSAmpPalService.exe; c: \ program dosyaları \ Intel \ BluetoothHS \ BTHSAmpPalService.exe [x]
S2 BBSvc; BingBar Hizmeti; c: \ program dosyaları (x86) \ Microsoft \ BingBar \ 7.3.132.0 \ BBSvc.exe; c: \ program dosyaları (x86) \ Microsoft \ BingBar \ 7.3.132.0 \ BBSvc.exe [x]
S2 Bluetooth Cihaz Monitörü; Bluetooth Cihaz Monitörü; c: \ program dosyaları (x86) \ Intel \ Bluetooth \ devmonsrv.exe; c: \ program dosyaları (x86) \ Intel \ Bluetooth \ devmonsrv.exe [x]
S2 Bluetooth OBEX Hizmeti; Bluetooth OBEX Hizmeti; c: \ program dosyaları (x86) \ Intel \ Bluetooth \ obexsrv.exe; c: \ program dosyaları (x86) \ Intel \ Bluetooth \ obexsrv.exe [x]
S2 BTHSSecurityMgr; Intel (R) Centrino (R) Kablosuz Bluetooth (R) 3.0 + Yüksek Hızlı Güvenlik Hizmeti; c: \ program dosyaları \ Intel \ BluetoothHS \ BTHSSecurityMgr.exe; c: \ program dosyaları \ Intel \ BluetoothHS \ BTHSSecurityMgr.exe [x]
S2 CodeMeter.exe; CodeMeter Çalışma Zamanı Sunucusu; c: \ program dosyaları (x86) \ CodeMeter \ Çalışma Zamanı \ bin \ CodeMeter.exe; c: \ program dosyaları (x86) \ CodeMeter \ Runtime \ bin \ CodeMeter.exe [x]
S2 IDMWFP; IDMWFP; c: \ windows \ system32 \ DRIVERS \ idmwfp.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ idmwfp.sys [x]
S2 TurboB; Turbo Boost UI Monitör sürücüsü; c: \ windows \ system32 \ DRIVERS \ TurboB.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ TurboB.sys [x]
S2 UNS; Intel (R) Yönetim ve Güvenlik Uygulaması Kullanıcı Bildirim Hizmeti; c: \ program dosyaları (x86) \ Intel \ Intel (R) Yönetim Motoru Bileşenleri \ UNS \ UNS.exe; c: \ program dosyaları (x86) \ Intel \ Intel (R) Yönetim Motoru Bileşenleri \ UNS \ UNS.exe [x]
S2 WCMVCAM; WebcamMax, WDM Video Çekimi; c: \ windows \ system32 \ DRIVERS \ wcmvcam64.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ wcmvcam64.sys [x]
S2 WDDMService; WDDMService; c: \ program dosyaları \ Western Digital \ WD SmartWare \ WDDMService.exe; c: \ program dosyaları \ Western Digital \ WD SmartWare \ WDDMService.exe [x]
S2 WDFMEService; WDFMEService; c: \ program dosyaları \ Western Digital \ WD SmartWare \ WDFME.exe; c: \ program dosyaları \ Western Digital \ WD SmartWare \ WDFME.exe [x]
S2 WDRulesService; WDRulesService; c: \ program dosyaları \ Western Digital \ WD SmartWare \ WDRulesEngine.exe; c: \ program dosyaları \ Western Digital \ WD SmartWare \ WDRulesEngine.exe [x]
S3 AMPPAL; Intel (R) Centrino (R) Bluetooth 3.0 + Yüksek Hızlı Sanal Adaptör; c: \ windows \ system32 \ DRIVERS \ AMPPAL.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ AMPPAL.sys [x]
S3 Bluetooth Medya Hizmeti; Bluetooth Medya Hizmeti; c: \ program dosyaları (x86) \ Intel \ Bluetooth \ mediasrv.exe; c: \ program dosyaları (x86) \ Intel \ Bluetooth \ mediasrv.exe [x]
S3 btmaux; Intel Bluetooth Yardımcı Servisi; c: \ windows \ system32 \ DRIVERS \ btmaux.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ btmaux.sys [x]
S3 btmhsf; btmhsf; c: \ windows \ system32 \ DRIVERS \ btmhsf.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ btmhsf.sys [x]
S3 clwvd; CyberLink Web Kamerası Sanal Sürücüsü; c: \ windows \ system32 \ DRIVERS \ clwvd.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ clwvd.sys [x]
S3 ETD; ELAN PS / 2 Bağlantı Noktası Giriş Cihazı; c: \ windows \ system32 \ DRIVERS \ ETD.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ ETD.sys [x]
S3 huawei_enumerator; huawei_enumerator; c: \ windows \ system32 \ DRIVERS \ ew_jubusenum.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ ew_jubusenum.sys [x]
S3 iBtFltCoex; iBtFltCoex; c: \ windows \ system32 \ DRIVERS \ iBtFltCoex.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ iBtFltCoex.sys [x]
S3 IntcDAud; Intel (R) Görüntü Sesi; c: \ windows \ system32 \ DRIVERS \ IntcDAud.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ IntcDAud.sys [x]
S3 iwdbus; IWD Veri Yolu Numaralandırıcısı; c: \ windows \ system32 \ DRIVERS \ iwdbus.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ iwdbus.sys [x]
S3 klkbdflt; Kaspersky Lab KLKBDFLT; c: \ windows \ system32 \ DRIVERS \ klkbdflt.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ klkbdflt.sys [x]
S3 klmouflt; Kaspersky Lab KLMOUFLT; c: \ windows \ system32 \ DRIVERS \ klmouflt.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ klmouflt.sys [x]
S3 MBAMProtector; MBAMProtector; c: \ windows \ system32 \ drivers \ mbam.sys; c: \ windows \ SYSNATIVE \ drivers \ mbam.sys [x]
S3 wdkmd; Intel WiDi KMD; c: \ windows \ system32 \ DRIVERS \ WDKMD.sys; c: \ windows \ SYSNATIVE \ DRIVERS \ WDKMD.sys [x]
.
.
'Zamanlanmış Görevler' klasörünün içeriği
.
2014-10-24 c: \ windows \ Tasks \ Adobe Flash Player Updater.job
- c: \ windows \ SysWOW64 \ Macromed \ Flash \ FlashPlayerUpdateService.exe [2013-09-23 16:53]
.
.
--------- X64 Girişleri -----------
.
.
[HKEY_LOCAL_MACHINE \ software \ microsoft \ windows \ currentversion \ explorer \ shelliconoverlayidentifiers \ IDM Kabuk Uzantısı]
@ = "{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
[Hkey_classes_root \ CLSID \ {CDC95B92-E27C-4745-A8C5-64A52A78855D}]
2014-04-21 10:02 25112 ---- a-w- c: \ program dosyaları (x86) \ Internet Download Manager \ IDMShellExt64.dll
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Run]
"RtHDVCpl" = "c: \ program dosyaları \ Realtek \ Audio \ HDA \ RAVCpl64.exe" [2011-06-25 11895400]
"BTMTrayAgent" = "c: \ program dosyaları (x86) \ Intel \ Bluetooth \ btmshell.dll" [2011-03-30 10372368]
"Windows Mobile Aygıt Merkezi" = "c: \ windows \ WindowsMobile \ wmdc.exe" [2007-05-31 660360]
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Windows]
"AppInit_DLLs" = C: \ WINDOWS \ System32 \ nvinitx.dll
.
------- Tamamlayıcı Tarama -------
.
uYerel Sayfa = c: \ windows \ system32 \ blank.htm
u Başlangıç Sayfası = yaklaşık: boş
mDefault_Search_URL =
www.google.com
mDefault_Page_URL = yaklaşık: boş
mStart Sayfası = yaklaşık: boş
mLocal Sayfa = c: \ windows \ SysWOW64 \ blank.htm
mArama Sayfası =
www.google.com
uInternet Ayarları, ProxyOverride = yerel
IE: Afişe Ekle - c: \ program dosyaları (x86) \ Kaspersky Lab \ Kaspersky Internet Security 2013 \ ie_banner_deny.htm
IE: Tüm bağlantıları IDM ile indirin - c: \ program dosyaları (x86) \ Internet Download Manager \ IEGetAll.htm
IE: IDM ile indir - c: \ program dosyaları (x86) \ Internet Download Manager \ IEExt.htm
IE: Microsoft Excel'e e & xport - c: \ progra ~ 2 \ MICROS ~ 1 \ Office12 \ EXCEL.EXE / 3000
TCP: DhcpNameServer = 23.253.94.129 8.8.8.8
TCP: Arabirimler \ {0F94A97A-365C-4B64-89C6-92B0743C79DC}: NameServer = 8.8.8.8,208.67.222.222
TCP: Arabirimler \ {7D4CCD51-620C-4141-805A-ED8762DEB07B}: NameServer = 8.8.8.8 4.2.2.4
TCP: Arabirimler \ {FF553CC1-79B4-4BFC-A997-24F1D3512431}: NameServer = 10.10.66.144 10.10.66.145
FF - ProfilePath - c: \ users \ Dandy \ AppData \ Roaming \ Mozilla \ Firefox \ Profiles \ uj83mbg1.default \
.
- - - - YETİMLER KALDIRILDI - - - -
.
Araç Çubuğu Kilitli - (dosya yok)
Wow6432Node-HKCU-Run-DLD.EXE - c: \ program dosyaları (x86) \ Download Direct \ DLD.exe
Wow6432Node-HKCU-Run-YTDownloader - c: \ program dosyaları (x86) \ YTDownloader \ YTDownloader.exe
Wow6432Node-HKLM-Run-YTDownloader - c: \ program dosyaları (x86) \ YTDownloader \ YTDownloader.exe
Wow6432Node-HKLM-Run- <İSİM YOK> - (dosya yok)
HKLM_Wow6432Node-ActiveSetup- {2D46B6DC-2207-486B-B523-A557E6D54B47} - başlat
Araç Çubuğu Kilitli - (dosya yok)
HKLM-Run-ETDCtrl - c: \ program dosyaları (x86) \ Elantech \ ETDCtrl.exe
.
.
.
--------------------- KİLİTLİ KAYIT ANAHTARLARI ---------------------
.
[HKEY_USERS \ .Default \ Software \ Microsoft \ Internet Explorer \ Onaylı Uzantılar]
@ Reddedildi: (2) (LocalSystem)
"{D4027C7F-154A-4066-A1AD-4243D8127440}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12,11,7f, 11,
d0,78,5b, 08.05, de, bb, 01.03, dd, 4c, 30.54
"{0055C089-8582-441B-A0BF-17B458C2A3A8}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12, e7, c3,46,
04, b0, cb, 75,01, df, a9,54, f4,5d, 9c, e7, bc
"{11111111-1111-1111-1111-110011221158}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12,7f, 12,02,
15,23,5f, 7f, 54,6e, 07,52,40,14,7c, 55,4c
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}" = heks: 51,66,7a, 6c, 4c, 1d, 38,12,72,0b, cc
1c, 9f, a6, ed, 07, da, 80, b9,17,89,70, f9, d7
"{9030D464-4C02-4ABF-8ECC-5164760863C6}" = heks: 51,66,7a, 6c, 4c, 1d, 38,12,0a, d7,23,
94,30,02, d1,0f, f1, o zaman 12,24,73,56,27, d2
"{AA609D72-8482-4076-8991-8CDAE5B93BCB}" = hex: 51,66,7a, 6c, 4c, 1d, 38,12,1c, 9e, 73,
ae, b0, ca, 18,05, f6,87, cf, 9a, e0, e7,7f, df
"{DBC80044-A445-435B-BC74-9C25C1C588A9}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12,2a, 03, db,
df, 77, ea, 35,06, c3,62, df, 65, c4,9b, cc, bd
"{E33CF602-D945-461A-83F0-819F76A199F8}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12,6c, f5,2f,
e7,77,97,74,03 fc, e6, C2, df, 73, ff, gg ec
"{E99987AC-6311-4686-B095-EB30B69F9258}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12, c2,84,8a,
baskı, 23,2d, e8,03 Cf, 83, a8,70, b3, c1, d6,4c
"{FF059E31-CC5A-4E2E-BF3B-96E929D65503}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12,5f, 9d, 16,
fb, 68,82,40,0b, c0,2d, d5, a9,2c, 88,11,17
"{BDEADE7F-C265-11D0-BCED-00A0C90AB50F}" = heks: 51,66,7a, 6c, 4c, 1d, 38,12,11, dd, F9,
b9,57,8c olmak, 54, C3, FB, 43 e0 cc, 54, f1,1b
"{EEC0F710-38B5-4ABA-99BF-EC87564A4E13}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12,7e, f4, d3,
ea, 87.76, d4,0f, e6, a9, c7,53,14,0a, 07
"{1DAD3AF3-EF2F-4F64-AC4B-11789189FCB6}" = onaltılık: 51,66,7a, 6c, 4c, 1d, 38,12,9d, 39, olmak,
19,1d, a1,0a, 0a, d3,5d, 52,38,94, d7, b8, a2
"{5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12,1d, cf, 77,
51,95, a1, d1,09, ee, 9c, 1f, b7, fe, e1, bb, 5b
"{73455575-E40C-433C-9784-C78DC7761455}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12,1b, 56,56,
77,3e, aa, 52,06, e8,92,84, cd, c2,28,50,41
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12, d5,94,07,
72, c2,98,42,03, c9, fd, 97,9a, f4,87,69,57
"{9E6D0D23-3D72-4A94-AE1F-2D167624E3D9}" = altıgen: 51,66,7a, 6c, 4c, 1d, 38,12,4d, 0e, 7e,
9a, 40,73, fa, 0f, d1,09,6e, 56,73,7a, a7, cd
.
[HKEY_USERS \ .Default \ Software \ Microsoft \ Internet Explorer \ ApprovedExtensionsMigration]
@ Reddedildi: (2) (LocalSystem)
"Zaman Damgası" = hex: 82,40, c3,0b, 7e, ec, cf, 01
.
[HKEY_USERS \ S-1-5-21-4152694092-3998405651-1245022814-1001_Classes \ Wow6432Node \ CLSID \ {7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Herkes)
@Allowed: (Oku) (RestrictedCode)
"Scansk" = hex (0): 3a, 92, ef, 08,64, a0,7f, 32, f3, db, 0e, a2,77,40,19,21, a6,62,6d, 26, d5 ,
60,47,20,52,44,8f, d5,26, ef, d0,92, cb, 0e, a5,02,7f, e1,38, a1,00,00,00,00,00,00, \
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Herkes)
@ = "FlashBroker"
"LocalizedString" = "c @: \ pencereler \ SysWOW64 \ Macromed \ Flaş \ FlashUtil11c_ActiveX.exe, -101"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {A483C63A-CDBC-426E-BF93-872502E8144E} \ yükseklik]
"Etkin" = dword: 00000001
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ Wow6432Node \ CLSID \ {A483C63A-CDBC-426E-BF93-872502E8144E} \ LocalServer32]
@ = "C: \ pencereler \ SysWOW64 \ Macromed \ Flaş \ FlashUtil11c_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {A483C63A-CDBC-426E-BF93-872502E8144E} \ tür kitaplığı]
@ = "{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB6E-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Herkes)
@ = "Shockwave Flash Nesnesi"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB6E-AE6D-11CF-96B8-444553540000} \ ınprocserver32]
@ = "C: \ pencereler \ SysWOW64 \ Macromed \ Flaş \ Flash11c.ocx"
"ThreadingModel" = "Daire"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB6E-AE6D-11CF-96B8-444553540000} \ MiscStatus]
@ = "0"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB6E-AE6D-11CF-96B8-444553540000} \ Progıd'ın]
@ = "ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB6E-AE6D-11CF-96B8-444553540000} \ ToolboxBitmap32]
@ = "c: \ windows \ SysWOW64 \ Macromed \ Flash \ Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB6E-AE6D-11CF-96B8-444553540000} \ tür kitaplığı]
@ = "{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB6E-AE6D-11CF-96B8-444553540000} \ Version]
@ = "1.0"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB6E-AE6D-11CF-96B8-444553540000} \ VersionIndependentProgID]
@ = "ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB70-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Herkes)
@ = "Macromedia Flash Fabrika Nesnesi"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB70-AE6D-11CF-96B8-444553540000} \ ınprocserver32]
@ = "C: \ pencereler \ SysWOW64 \ Macromed \ Flaş \ Flash11c.ocx"
"ThreadingModel" = "Daire"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB70-AE6D-11CF-96B8-444553540000} \ Progıd'ın]
@ = "FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB70-AE6D-11CF-96B8-444553540000} \ ToolboxBitmap32]
@ = "c: \ windows \ SysWOW64 \ Macromed \ Flash \ Flash11c.ocx, 1"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB70-AE6D-11CF-96B8-444553540000} \ tür kitaplığı]
@ = "{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB70-AE6D-11CF-96B8-444553540000} \ Version]
@ = "1.0"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ CLSID \ {D27CDB70-AE6D-11CF-96B8-444553540000} \ VersionIndependentProgID]
@ = "FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ Ara \ {E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Herkes)
@ = "IFlashBroker4"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ Ara \ {E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F} \ ProxyStubClsid32]
@ = "{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Sınıfları \ Wow6432Node \ Ara \ {E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F} \ tür kitaplığı]
@ = "{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Sürüm" = "1.0"
.
[HKEY_LOCAL_MACHINE \ SOFTWARE \ Wow6432Node \ Microsoft \ Windows CE Services]
"SymbolicLinkValue" = heks (6): 5c, 00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c, 00,4d, 00,41,00,43,00,48,00,49,00,4e, 00,45,00,5c, 00,53,00,4f, 00,46,00, \
.
[HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ Class \ {4D36E96D-E325-11CE-BFC1-08002BE10318} \ 0000 \ AllUserSettings]
@ Reddedildi: (A) (Kullanıcılar)
@Denied: (A) (Herkes)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial" = kelime: 00000000
.
[HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ Class \ {4D36E96D-E325-11CE-BFC1-08002BE10318} \ 0001 \ AllUserSettings]
@ Reddedildi: (A) (Kullanıcılar)
@Denied: (A) (Herkes)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial" = kelime: 00000000
.
[HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ Class \ {4D36E96D-E325-11CE-BFC1-08002BE10318} \ 0002 \ AllUserSettings]
@ Reddedildi: (A) (Kullanıcılar)
@Denied: (A) (Herkes)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial" = kelime: 00000000
.
[HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ Class \ {4D36E96D-E325-11CE-BFC1-08002BE10318} \ 0003 \ AllUserSettings]
@ Reddedildi: (A) (Kullanıcılar)
@Denied: (A) (Herkes)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial" = kelime: 00000000
.
[HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ Class \ {4D36E96D-E325-11CE-BFC1-08002BE10318} \ 0004 \ AllUserSettings]
@ Reddedildi: (A) (Kullanıcılar)
@Denied: (A) (Herkes)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial" = kelime: 00000000
.
[HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ Class \ {4D36E96D-E325-11CE-BFC1-08002BE10318} \ 0005 \ AllUserSettings]
@ Reddedildi: (A) (Kullanıcılar)
@Denied: (A) (Herkes)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial" = kelime: 00000000
.
[HKEY_LOCAL_MACHINE \ SYSTEM \ ControlSet001 \ Control \ PCW \ Güvenlik]
@Denied: (Full) (Herkes)
.
------------------------ Diğer Çalışan İşlemler ----------------------- -
.
c: \ program dosyaları (x86) \ Ortak Dosyalar \ Adobe \ ARM \ 1.0 \ armsvc.exe
c: \ program dosyaları (x86) \ CyberLink \ Paylaşılan dosyalar \ RichVideo.exe
c: \ program dosyaları (x86) \ Intel \ Bluetooth \ BTPlayerCtrl.exe
c: \ program dosyaları (x86) \ Intel \ Intel (R) Yönetim Motoru Bileşenleri \ LMS \ LMS.exe
c: \ program dosyaları (x86) \ NVIDIA Corporation \ NVIDIA Updatus \ daemonu.exe
.
**************************************************************************
.
Tamamlanma süresi: 2014-10-25 08:56:43 - makine yeniden başlatıldı
ComboFix-karantinaya alınmış dosyalar.txt 2014-10-25 05:26
.
Çalışma Öncesi: 184.188.878.848 bayt ücretsiz
Post-Run: 186.303.815.680 bayt ücretsiz
.
- - Dosya Sonu - - B52EBB18701F5F23BA871DD5F1B329A7