mrb arkadaşlar ben combofixi çalıştırdımda rapor verdi bunu incelermisiniz acaba .... ComboFix 14-04-26.01 - senkron 27.04.2014 13:44:26.7.2 - x86 Running from: c:\users\senkron\Downloads\ComboFix.exe . . ((((((((((((((((((((((((( Files Created from 2014-03-27 to 2014-04-27 ))))))))))))))))))))))))))))))) . . 2014-04-27 10:53 . 2014-04-27 10:53 -------- d-----w- c:\users\Public\AppData\Local\temp 2014-04-27 10:53 . 2014-04-27 10:53 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-04-27 08:18 . 2014-04-17 02:32 8050496 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{97EC8785-0139-481D-897C-54D946B0316F}\mpengine.dll 2014-04-20 07:46 . 2014-01-09 02:22 5694464 ----a-w- c:\windows\system32\mstscax.dll 2014-04-19 10:59 . 2014-04-19 10:58 9216 ----a-w- c:\windows\system32\drivers\massfilter.sys 2014-04-19 10:59 . 2014-04-19 10:58 116736 ----a-w- c:\windows\system32\drivers\ZTEusbnet.sys 2014-04-19 10:59 . 2014-04-19 10:58 107776 ----a-w- c:\windows\system32\drivers\ZTEusbser6k.sys 2014-04-19 10:59 . 2014-04-19 10:58 107776 ----a-w- c:\windows\system32\drivers\ZTEusbnmea.sys 2014-04-19 10:59 . 2014-04-19 10:58 107776 ----a-w- c:\windows\system32\drivers\ZTEusbmdm6k.sys 2014-04-19 10:59 . 2014-04-20 10:42 -------- d-----w- c:\users\senkron\AppData\Roaming\AveaConnectionManager 2014-04-19 10:58 . 2014-04-19 10:59 -------- d-----w- c:\program files\AveaConnectionManager 2014-04-19 09:39 . 2012-08-23 14:44 14848 ----a-w- c:\windows\system32\drivers\rdpvideominiport.sys 2014-04-19 09:39 . 2012-08-23 13:52 12800 ----a-w- c:\windows\system32\RdpGroupPolicyExtension.dll 2014-04-19 09:39 . 2012-08-23 14:48 221184 ----a-w- c:\windows\system32\rdpudd.dll 2014-04-19 09:39 . 2012-08-23 11:12 192000 ----a-w- c:\windows\system32\rdpendp_winip.dll 2014-04-19 09:39 . 2012-08-23 10:08 2739712 ----a-w- c:\windows\system32\rdpcorets.dll 2014-04-19 09:39 . 2013-10-01 23:45 32256 ----a-w- c:\windows\system32\TsUsbGDCoInstaller.dll 2014-04-19 09:38 . 2013-10-02 00:32 12800 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2014-04-19 09:38 . 2013-10-02 00:42 49152 ----a-w- c:\windows\system32\drivers\TsUsbFlt.sys 2014-04-19 09:38 . 2013-10-02 00:30 14336 ----a-w- c:\windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2014-04-19 09:38 . 2013-10-02 00:14 50176 ----a-w- c:\windows\system32\MsRdpWebAccess.dll 2014-04-19 09:38 . 2013-10-02 00:14 17920 ----a-w- c:\windows\system32\wksprtPS.dll 2014-04-19 09:38 . 2013-10-01 23:58 53248 ----a-w- c:\windows\system32\tsgqec.dll 2014-04-19 09:38 . 2013-10-01 23:08 855552 ----a-w- c:\windows\system32\rdvidcrl.dll 2014-04-19 09:38 . 2013-10-01 23:00 76288 ----a-w- c:\windows\system32\TSWbPrxy.exe 2014-04-19 09:38 . 2013-10-01 22:53 350208 ----a-w- c:\windows\system32\wksprt.exe 2014-04-19 09:38 . 2013-10-01 22:34 1068544 ----a-w- c:\windows\system32\mstsc.exe 2014-04-19 09:38 . 2014-04-19 09:38 -------- d-----w- C:\Intel 2014-04-19 09:35 . 2013-09-25 01:57 792576 ----a-w- c:\windows\system32\TSWorkspace.dll 2014-04-19 09:35 . 2012-05-04 09:59 514560 ----a-w- c:\windows\system32\qdvd.dll 2014-04-14 06:40 . 2014-04-14 06:40 -------- d-----w- c:\program files\PhotoRestorer 2014-04-09 22:38 . 2014-04-09 22:38 -------- d-sh--w- c:\users\senkron\AppData\Local\EmieUserList 2014-04-09 22:38 . 2014-04-09 22:38 -------- d-sh--w- c:\users\senkron\AppData\Local\EmieSiteList 2014-04-09 22:21 . 2014-03-06 07:46 4254720 ----a-w- c:\windows\system32\jscript9.dll 2014-04-09 10:11 . 2014-02-04 02:07 149440 ----a-w- c:\windows\system32\drivers\storport.sys 2014-04-09 10:11 . 2014-02-04 02:07 234432 ----a-w- c:\windows\system32\drivers\msiscsi.sys 2014-04-09 10:11 . 2014-02-04 02:07 27072 ----a-w- c:\windows\system32\drivers\Diskdump.sys 2014-04-09 10:11 . 2014-02-04 02:00 2048 ----a-w- c:\windows\system32\iologmsg.dll 2014-04-09 10:11 . 2014-01-24 02:18 1212352 ----a-w- c:\windows\system32\drivers\ntfs.sys 2014-04-09 08:19 . 2014-04-09 09:57 -------- d-----w- c:\program files\ExpressFiles 2014-04-09 08:19 . 2014-04-09 08:19 -------- d-----w- c:\users\senkron\AppData\Roaming\ExpressFiles 2014-04-07 11:07 . 2014-04-09 09:57 -------- d-----w- c:\program files\Elcomsoft Password Recovery 2014-04-06 07:48 . 2014-04-06 07:48 -------- d-----w- c:\windows\system32\wbem\MOF\good 2014-04-06 07:48 . 2014-04-06 07:48 -------- d-----w- c:\windows\system32\wbem\MOF\bad 2014-04-06 07:48 . 2014-04-06 07:48 -------- d-----w- c:\windows\system32\wbem\Logs 2014-04-02 08:54 . 2014-04-02 09:56 -------- d-----w- c:\program files\NCH Software 2014-03-29 08:52 . 2014-04-27 10:53 -------- d-----w- c:\users\senkron\AppData\Local\temp 2014-03-28 13:17 . 2014-04-01 23:14 -------- d-----w- c:\program files\7-Data Card Recovery . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-03-31 06:35 . 2013-06-21 16:29 231584 ------w- c:\windows\system32\MpSigStub.exe 2014-03-12 11:19 . 2013-06-21 16:31 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2014-03-12 11:19 . 2013-06-21 16:31 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-02-13 23:30 . 2013-06-26 21:29 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup-2\Markup.dll 2014-02-13 23:30 . 2013-06-22 22:22 524624 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2014-02-09 11:39 . 2014-01-28 23:49 527674 ----a-w- c:\users\senkron\YouTube.js 2014-02-09 10:28 . 2013-06-22 22:22 48648 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\Markup.dll 2014-02-08 13:08 . 2014-02-08 13:08 64168 ----a-w- c:\windows\system32\drivers\aswStm.sys 2014-02-08 13:08 . 2014-02-08 13:08 180248 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2014-02-08 13:08 . 2014-02-08 13:08 775952 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2014-02-08 13:08 . 2014-02-08 13:08 410784 ----a-w- c:\windows\system32\drivers\aswSP.sys 2014-02-08 13:08 . 2014-02-08 13:08 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2014-02-08 13:08 . 2014-02-08 13:08 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2014-02-08 13:08 . 2014-02-08 13:08 79720 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2014-02-08 13:08 . 2014-02-08 13:08 270240 ----a-w- c:\windows\system32\aswBoot.exe 2014-02-08 13:08 . 2014-02-08 13:08 43152 ----a-w- c:\windows\avastSS.scr 2014-02-07 01:07 . 2014-03-12 11:18 2349056 ----a-w- c:\windows\system32\win32k.sys 2014-02-04 02:04 . 2014-03-12 11:18 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-02-04 02:04 . 2014-03-12 11:18 509440 ----a-w- c:\windows\system32\qedit.dll 2014-02-02 10:05 . 2013-06-26 21:29 524624 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight-2\SpotlightResources.dll 2014-01-29 20:12 . 2014-01-29 20:12 279000 ----a-w- c:\windows\system32\IntelCpHeciSvc.exe 2014-01-29 20:12 . 2014-01-29 20:12 437248 ----a-w- c:\windows\system32\igfxrrus.lrc 2014-01-29 20:12 . 2014-01-29 20:12 437248 ----a-w- c:\windows\system32\igfxrrom.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436736 ----a-w- c:\windows\system32\igfxrsky.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436736 ----a-w- c:\windows\system32\igfxrptg.lrc 2014-01-29 20:12 . 2014-01-29 20:12 435712 ----a-w- c:\windows\system32\igfxrtrk.lrc 2014-01-29 20:12 . 2014-01-29 20:12 435712 ----a-w- c:\windows\system32\igfxrsve.lrc 2014-01-29 20:12 . 2014-01-29 20:12 435712 ----a-w- c:\windows\system32\igfxrslv.lrc 2014-01-29 20:12 . 2014-01-29 20:12 435712 ----a-w- c:\windows\system32\igfxrptb.lrc 2014-01-29 20:12 . 2014-01-29 20:12 435200 ----a-w- c:\windows\system32\igfxrtha.lrc 2014-01-29 20:12 . 2014-01-29 20:12 286208 ----a-w- c:\windows\system32\igfxTMM.dll 2014-01-29 20:12 . 2014-01-29 20:12 271832 ----a-w- c:\windows\system32\igfxsrvc.exe 2014-01-29 20:12 . 2014-01-29 20:12 145880 ----a-w- c:\windows\system32\igfxtray.exe 2014-01-29 20:12 . 2014-01-29 20:12 102400 ----a-w- c:\windows\system32\igfxCoIn_v3347.dll 2014-01-29 20:12 . 2012-12-13 23:02 59904 ----a-w- c:\windows\system32\igfxsrvc.dll 2014-01-29 20:12 . 2014-01-29 20:12 9023488 ----a-w- c:\windows\system32\igfxress.dll 2014-01-29 20:12 . 2014-01-29 20:12 437760 ----a-w- c:\windows\system32\igfxrfra.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436736 ----a-w- c:\windows\system32\igfxrplk.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436736 ----a-w- c:\windows\system32\igfxrnld.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436736 ----a-w- c:\windows\system32\igfxrita.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436736 ----a-w- c:\windows\system32\igfxrhrv.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436224 ----a-w- c:\windows\system32\igfxrhun.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436224 ----a-w- c:\windows\system32\igfxrfin.lrc 2014-01-29 20:12 . 2014-01-29 20:12 435712 ----a-w- c:\windows\system32\igfxrnor.lrc 2014-01-29 20:12 . 2014-01-29 20:12 433664 ----a-w- c:\windows\system32\igfxrheb.lrc 2014-01-29 20:12 . 2014-01-29 20:12 430080 ----a-w- c:\windows\system32\igfxrjpn.lrc 2014-01-29 20:12 . 2014-01-29 20:12 429056 ----a-w- c:\windows\system32\igfxrkor.lrc 2014-01-29 20:12 . 2014-01-29 20:12 9728 ----a-w- c:\windows\system32\IGFXDEVLib.dll 2014-01-29 20:12 . 2014-01-29 20:12 931840 ----a-w- c:\windows\system32\igfxcmrt32.dll 2014-01-29 20:12 . 2014-01-29 20:12 542720 ----a-w- c:\windows\system32\igfx11cmrt32.dll 2014-01-29 20:12 . 2014-01-29 20:12 438272 ----a-w- c:\windows\system32\igfxrell.lrc 2014-01-29 20:12 . 2014-01-29 20:12 437760 ----a-w- c:\windows\system32\igfxresn.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436736 ----a-w- c:\windows\system32\igfxrdeu.lrc 2014-01-29 20:12 . 2014-01-29 20:12 436224 ----a-w- c:\windows\system32\igfxrcsy.lrc 2014-01-29 20:12 . 2014-01-29 20:12 435200 ----a-w- c:\windows\system32\igfxrdan.lrc 2014-01-29 20:12 . 2014-01-29 20:12 433664 ----a-w- c:\windows\system32\igfxrara.lrc 2014-01-29 20:12 . 2014-01-29 20:12 427008 ----a-w- c:\windows\system32\igfxrcht.lrc 2014-01-29 20:12 . 2014-01-29 20:12 426496 ----a-w- c:\windows\system32\igfxrchs.lrc 2014-01-29 20:12 . 2014-01-29 20:12 3121152 ----a-w- c:\windows\system32\igfxcmjit32.dll 2014-01-29 20:12 . 2014-01-29 20:12 284160 ----a-w- c:\windows\system32\igfxrenu.lrc 2014-01-29 20:12 . 2014-01-29 20:12 25088 ----a-w- c:\windows\system32\igfxexps.dll 2014-01-29 20:12 . 2014-01-29 20:12 199128 ----a-w- c:\windows\system32\igfxext.exe 2014-01-29 20:12 . 2014-01-29 20:12 189912 ----a-w- c:\windows\system32\igfxpers.exe 2014-01-29 20:12 . 2014-01-29 20:12 130048 ----a-w- c:\windows\system32\igfxdo.dll 2014-01-29 20:12 . 2014-01-29 20:12 120320 ----a-w- c:\windows\system32\igfxcpl.cpl 2014-01-29 20:12 . 2012-12-13 23:02 313344 ----a-w- c:\windows\system32\igfxpph.dll 2014-01-29 20:12 . 2012-12-13 23:02 330752 ----a-w- c:\windows\system32\igfxdev.dll 2014-01-29 20:12 . 2014-01-29 20:12 11049472 ----a-w- c:\windows\system32\igdumd32.dll 2014-01-29 20:12 . 2014-01-29 20:12 3768320 ----a-w- c:\windows\system32\drivers\igdkmd32.sys 2014-01-29 20:12 . 2014-01-29 20:12 77312 ----a-w- c:\windows\system32\igdde32.dll 2014-01-29 20:12 . 2012-12-13 23:02 11176448 ----a-w- c:\windows\system32\igd10umd32.dll 2014-01-29 20:12 . 2014-01-29 20:12 10812928 ----a-w- c:\windows\system32\ig4icd32.dll 2014-01-29 20:12 . 2014-01-29 20:12 6231512 ----a-w- c:\windows\system32\GfxUI.exe 2014-01-29 20:12 . 2014-01-29 20:12 181208 ----a-w- c:\windows\system32\hkcmd.exe 2014-01-29 20:12 . 2014-01-29 20:12 175616 ----a-w- c:\windows\system32\gfxSrvc.dll 2014-01-29 20:12 . 2012-12-13 23:02 96256 ----a-w- c:\windows\system32\hccutils.dll 2014-01-29 02:06 . 2014-03-12 11:18 381440 ----a-w- c:\windows\system32\wer.dll 2014-01-29 00:29 . 2014-01-29 00:29 621056 ----a-w- c:\programdata\SQLite.Interop.dll 2014-01-29 00:29 . 2014-01-29 00:29 165376 ----a-w- c:\programdata\System.Data.SQLite.dll 2014-01-28 02:07 . 2014-03-12 11:18 185344 ----a-w- c:\windows\system32\wwansvc.dll 2014-01-27 23:43 . 2014-01-27 23:43 1175700 ----a-w- c:\windows\system32\RainySs.scr 2011-06-09 09:03 . 2013-07-13 12:04 3486088 ----a-w- c:\program files\Common Files\ApnToolbarInstaller.exe 2011-06-09 09:03 . 2013-07-13 12:04 143240 ----a-w- c:\program files\Common Files\ApnStub.exe . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2014-02-08 13:08 259464 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2014-04-22 39408] "ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2011-12-20 2696512] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2010-07-15 1860904] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2011-06-28 10127976] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-04 3774312] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2014-01-29 145880] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2014-01-29 181208] "Persistence"="c:\windows\system32\igfxpers.exe" [2014-01-29 189912] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2013-08-27 280576] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) . [HKLM\~\startupfolder\C:^Users^senkron^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Ekran Kırpıcı ve Başlatıcı.lnk] path=c:\users\senkron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Ekran Kırpıcı ve Başlatıcı.lnk backup=c:\windows\pss\OneNote 2007 Ekran Kırpıcı ve Başlatıcı.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2013-11-14 14:42 20584608 ----a-r- c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] 2013-07-23 22:57 84576 ----a-w- c:\program files\Winamp\winampa.exe . [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "Google Update"="c:\users\senkron\AppData\Local\Google\Update\GoogleUpdate.exe" /c . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" . R1 iSafeNetFilter;iSafeNetFilter;c:\program files\iSafe\iSafeNetFilter.sys [x] R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\DRIVERS\StarPortLite.sys [x] R2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-10-09 3275136] R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2013-09-05 171680] R3 BthAvrcp;Bluetooth AVRCP Profile;c:\windows\system32\DRIVERS\BthAvrcp.sys [2009-08-13 22528] R3 EWSASERV;EWSA Control Service;c:\program files\Elcomsoft Password Recovery\Elcomsoft Wireless Security Auditor\ewsaserv.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-03-06 108032] R3 iSafeKrnl;iSafeKrnl;c:\program files\iSafe\iSafeKrnl.sys [x] R3 netr28u;Vista için RT2870 USB Kablosuz LAN Kartı Sürücüsü;c:\windows\system32\DRIVERS\netr28u.sys [2009-07-13 657408] R3 netr73;Vista için RT73 USB Kablosuz LAN Kartı Sürücüsü;c:\windows\system32\DRIVERS\netr73.sys [2009-07-13 545792] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152] R3 WatAdminSvc;Windows Etkinleştirme Teknolojileri Hizmeti;c:\windows\system32\Wat\WatAdminSvc.exe [2013-08-11 1343400] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S0 EMSC;Embedded System Control;c:\windows\system32\DRIVERS\EMSC.SYS [2009-11-16 14960] S0 sptd;sptd;c:\windows\\SystemRoot\System32\Drivers\sptd.sys [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-02-08 775952] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-02-08 410784] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-02-08 67824] S2 NAUpdate;Nero Güncelleme;c:\program files\Nero\Update\NASvc.exe [2010-05-04 503080] S2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-01-27 50704] S2 WiseFS;WiseFS;c:\program files\Wise\Wise Folder Hider\WiseFs32.sys [2014-02-27 9768] S2 WTGService;WTGService;c:\program files\AveaConnectionManager\WTGService.exe [2013-02-12 342584] S3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-02-08 64168] S3 MEI;Intel(R) Management Engine Interface ;c:\windows\system32\DRIVERS\TeeDriver.sys [2013-03-20 85976] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2013-03-04 643656] S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [2010-06-11 1015328] . . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-04-08 22:30 1077576 ----a-w- c:\program files\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2014-04-27 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-21 11:19] . 2014-04-26 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-638756576-2537300043-4041083303-1000Core.job - c:\users\senkron\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-24 23:35] . 2014-04-27 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-638756576-2537300043-4041083303-1000UA.job - c:\users\senkron\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-24 23:35] . 2014-04-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-09-19 22:51] . 2014-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-09-19 22:51] . 2014-04-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-638756576-2537300043-4041083303-1000Core.job - c:\users\senkron\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-28 13:57] . 2014-04-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-638756576-2537300043-4041083303-1000UA.job - c:\users\senkron\AppData\Local\Google\Update\GoogleUpdate.exe [2014-02-28 13:57] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.bing.com/ mStart Page = hxxp://www.google.com IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Microsoft Excel'e &Ver - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000 TCP: Interfaces\{3C537200-526C-480B-A8B9-3884A57CEFCA}: NameServer = 156.154.70.25,156.154.71.25 . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-638756576-2537300043-4041083303-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*" ] @Class="Shell" @Allowed: (Read) (RestrictedCode) . [HKEY_USERS\S-1-5-21-638756576-2537300043-4041083303-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*" \OpenWithList] @Class="Shell" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2014-04-27 13:55:20 ComboFix-quarantined-files.txt 2014-04-27 10:55 ComboFix2.txt 2014-03-29 08:52 ComboFix3.txt 2014-02-02 11:11 ComboFix4.txt 2013-12-06 09:28 ComboFix5.txt 2014-04-27 10:42 . Pre-Run: 71.415.336.960 bayt boş Post-Run: 71.109.263.360 bayt boş . - - End Of File - - 2A7859F7252301EAF566C4DCACFF3D2A A36C5E4F47E84449FF07ED3517B43A31