PART 2
O1 HOSTS File: ([2014.04.03 23:41:27 | 000,000,492 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O2:
64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:
64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:
64bit: - HKU\S-1-5-21-2950337373-4117638349-1153287397-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-2950337373-4117638349-1153287397-1000\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [USB Security] C:\Program Files (x86)\USB Disk Security\USBGuard.exe (Zbshareware Lab)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2950337373-4117638349-1153287397-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2950337373-4117638349-1153287397-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Adobe PDF'ye dönüştür - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Bağ Hedefini PDF’ye Dönüştür - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Bağ Hedefini PDF’ye Ekle - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Varolan PDF’ye Ekle - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Adobe PDF'ye dönüştür - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Bağ Hedefini PDF’ye Dönüştür - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Bağ Hedefini PDF’ye Ekle - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Varolan PDF’ye Ekle - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll (National Instruments Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\National Instruments\Shared\mDNS Responder\nimdnsNSP.dll (National Instruments Corporation)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.168.98.196 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B7D8481C-6EED-4716-A734-C513E9D6B1CC}: DhcpNameServer = 68.168.98.196 8.8.8.8
O18:
64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014.03.26 03:23:57 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014.04.08 15:40:48 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
[2014.04.08 15:29:17 | 001,016,261 | ---- | C] (Thisisu) -- C:\Users\pc\Desktop\JRT.exe
[2014.04.07 22:51:44 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014.04.07 22:51:39 | 000,000,000 | ---D | C] -- C:\windows\temp
[2014.04.07 22:43:27 | 000,000,000 | ---D | C] -- C:\ComboFix
[2014.04.07 03:53:14 | 005,195,663 | R--- | C] (Swearware) -- C:\Users\pc\Desktop\ComboFix.exe
[2014.04.06 22:40:37 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\mbarrrt
[2014.04.06 22:34:46 | 012,589,848 | ---- | C] (Malwarebytes Corp.) -- C:\Users\pc\Desktop\mbar-1.07.0.1009.exe
[2014.04.06 05:49:31 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\MP ^^
[2014.04.06 02:18:54 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\Videos – Audioslides_files
[2014.04.06 00:44:47 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\ECG MATLAB
[2014.04.05 20:45:11 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\ebooookkkss
[2014.04.05 06:41:05 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\Phil_Collins-Greatest_Hits_2010
[2014.04.04 07:40:25 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\Pum HJ Desk and Pol - TechSpot Forums_files
[2014.04.04 07:01:56 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2014.04.04 06:46:54 | 000,000,000 | ---D | C] -- C:\windows\Sun
[2014.04.04 06:36:03 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\Remove Outdated Browser Detected pop-up virus (Removal Guide)_files
[2014.04.04 05:11:38 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\pearl
[2014.04.03 20:50:43 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\java C matlab
[2014.04.03 19:28:18 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014.04.01 04:02:32 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2014.04.01 04:01:30 | 010,971,424 | ---- | C] (SurfRight B.V.) -- C:\Users\pc\Desktop\HitmanPro_x64.exe
[2014.04.01 03:45:24 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\RK_Quarantine
[2014.04.01 03:31:00 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\Remove PWS-Zbot virus (Removal Instructions)_files
[2014.04.01 01:38:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2014.03.31 23:57:43 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\ScanSpyware
[2014.03.31 23:55:29 | 004,233,347 | ---- | C] (ScanSpyware.Net ) -- C:\Users\pc\Desktop\ScanSpyware_3.9.2.2.exe
[2014.03.31 05:46:26 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\schoolmates
[2014.03.31 05:41:01 | 000,000,000 | ---D | C] -- C:\windows\Fated Haven - Chapter One
[2014.03.31 05:41:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Fated Haven - Chapter One
[2014.03.30 02:21:03 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\TheFlyingDutchman
[2014.03.30 02:20:27 | 000,000,000 | ---D | C] -- C:\windows\The Flying Dutchman - In The Ghost Prison
[2014.03.30 02:00:00 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Picsoft
[2014.03.30 01:59:06 | 000,000,000 | ---D | C] -- C:\windows\Mini Robot Wars
[2014.03.30 01:00:06 | 015,320,504 | ---- | C] (Greatis Software, LLC. ) -- C:\Users\pc\Desktop\unhackme_setup.exe
[2014.03.29 14:50:22 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\directx
[2014.03.29 13:10:41 | 000,000,000 | ---D | C] -- C:\Users\pc\Documents\Telltale Games
[2014.03.29 13:09:04 | 000,000,000 | ---D | C] -- C:\windows\Puzzle Agent 2
[2014.03.29 13:05:33 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Meridian93
[2014.03.29 13:03:09 | 000,000,000 | ---D | C] -- C:\windows\Fruit Farm
[2014.03.29 13:00:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Phenomedia
[2014.03.29 05:41:54 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Local\Tales of Lagoona
[2014.03.29 05:41:06 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tales of Lagoona - Orphans of the Ocean
[2014.03.29 05:38:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Tales of Lagoona - Orphans of the Ocean
[2014.03.29 05:36:27 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\JQ
[2014.03.29 05:34:15 | 000,000,000 | ---D | C] -- C:\windows\Julia's Quest - United Kingdom
[2014.03.29 05:28:36 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\HdO Adventure
[2014.03.29 05:25:57 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Boolat Games
[2014.03.29 05:24:47 | 000,000,000 | ---D | C] -- C:\windows\Timeless - The Forgotten Town Collector's Edition
[2014.03.29 05:09:52 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\BULKYPIX
[2014.03.29 05:09:40 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Saving Private Sheep
[2014.03.29 05:06:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Saving Private Sheep
[2014.03.29 04:07:55 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Mayan Puzzle
[2014.03.29 04:07:35 | 000,000,000 | ---D | C] -- C:\Users\pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Mayan Puzzle
[2014.03.29 04:07:33 | 000,000,000 | ---D | C] -- C:\windows\Mayan Puzzle
[2014.03.29 04:07:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mayan Puzzle
[2014.03.29 01:04:31 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbamchameleon.sys
[2014.03.29 01:04:31 | 000,063,192 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mwac.sys
[2014.03.29 01:04:31 | 000,025,816 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2014.03.29 01:04:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes Anti-Malware
[2014.03.29 00:55:10 | 017,523,384 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\pc\Desktop\mbam-setup-2.0.0.1000 (1) - Kopya.exe
[2014.03.28 19:10:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Anti-Malware
[2014.03.28 19:10:41 | 000,000,000 | ---D | C] -- C:\Users\pc\Documents\Anti-Malware
[2014.03.28 18:51:39 | 000,119,512 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.03.27 22:15:45 | 000,000,000 | ---D | C] -- C:\Users\pc\Documents\ProcAlyzer Dumps
[2014.03.27 22:01:28 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\Trojan virus.. removed but still need help - TechSpot Forums_files
[2014.03.27 14:24:59 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\çöp
[2014.03.27 01:07:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2014.03.27 01:07:46 | 000,021,040 | ---- | C] (Safer Networking Limited) -- C:\windows\SysNative\sdnclean64.exe
[2014.03.27 01:07:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2014.03.26 23:22:45 | 000,000,000 | ---D | C] -- C:\spybotSearch&Destroy
[2014.03.26 22:55:56 | 000,518,144 | ---- | C] (SteelWerX) -- C:\windows\SWREG.exe
[2014.03.26 22:55:56 | 000,406,528 | ---- | C] (SteelWerX) -- C:\windows\SWSC.exe
[2014.03.26 22:55:56 | 000,060,416 | ---- | C] (NirSoft) -- C:\windows\NIRCMD.exe
[2014.03.26 22:48:30 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2014.03.26 21:41:23 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014.03.26 05:33:20 | 000,000,000 | ---D | C] -- C:\Users\pc\Documents\RegRun2
[2014.03.26 05:32:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UnHackMe
[2014.03.26 05:13:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Enigma Software Group
[2014.03.26 03:23:16 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2014.03.26 03:22:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2014.03.25 02:56:16 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\twist measurement dsp
[2014.03.24 05:27:14 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\E B O O K simulink sensor mems nano biologic chemical snsor mechatronics photonics PIC simulinl
[2014.03.17 14:13:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2014.03.17 14:13:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2014.03.17 14:13:22 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
[2014.03.17 03:02:57 | 000,000,000 | ---D | C] -- C:\Users\pc\Desktop\cihan ödev son
========== Files - Modified Within 30 Days ==========
[2014.04.08 15:45:01 | 000,000,830 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
[2014.04.08 15:40:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\pc\Desktop\OTL.exe
[2014.04.08 15:35:00 | 000,001,020 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA1cef2b99b02ecfc.job
[2014.04.08 15:34:27 | 000,016,752 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014.04.08 15:34:27 | 000,016,752 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014.04.08 15:29:25 | 001,016,261 | ---- | M] (Thisisu) -- C:\Users\pc\Desktop\JRT.exe
[2014.04.08 15:29:00 | 000,000,814 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2014.04.08 15:28:08 | 000,119,512 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\MBAMSwissArmy.sys
[2014.04.08 15:26:02 | 000,000,828 | ---- | M] () -- C:\windows\tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
[2014.04.08 15:25:59 | 000,001,008 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2014.04.08 15:25:50 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2014.04.08 15:25:46 | 2037,616,639 | -HS- | M] () -- C:\hiberfil.sys
[2014.04.08 15:22:35 | 001,426,178 | ---- | M] () -- C:\Users\pc\Desktop\adwcleaner (1).exe
[2014.04.08 15:02:18 | 001,570,970 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2014.04.08 15:02:18 | 000,656,940 | ---- | M] () -- C:\windows\SysNative\perfh01F.dat
[2014.04.08 15:02:18 | 000,654,464 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2014.04.08 15:02:18 | 000,140,336 | ---- | M] () -- C:\windows\SysNative\perfc01F.dat
[2014.04.08 15:02:18 | 000,122,336 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2014.04.08 00:37:54 | 005,295,612 | ---- | M] () -- C:\Users\pc\Desktop\pisa 2012 Creative Problem Solving.pdf
[2014.04.07 03:54:13 | 005,195,663 | R--- | M] (Swearware) -- C:\Users\pc\Desktop\ComboFix.exe
[2014.04.07 00:31:05 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbamchameleon.sys
[2014.04.06 22:35:08 | 012,589,848 | ---- | M] (Malwarebytes Corp.) -- C:\Users\pc\Desktop\mbar-1.07.0.1009.exe
[2014.04.06 22:23:18 | 003,972,608 | ---- | M] () -- C:\Users\pc\Desktop\RogueKiller.exe
[2014.04.06 03:54:18 | 000,007,168 | ---- | M] () -- C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014.04.06 02:18:54 | 000,050,078 | ---- | M] () -- C:\Users\pc\Desktop\Videos – Audioslides.htm
[2014.04.06 00:51:21 | 000,608,968 | ---- | M] () -- C:\Users\pc\Desktop\SignalProcessingofECGSignalsinMatlab.pdf
[2014.04.05 16:55:51 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.04.05 06:56:17 | 000,043,703 | -HS- | M] () -- C:\Users\pc\Desktop\Folder.jpg
[2014.04.05 06:56:17 | 000,009,134 | -HS- | M] () -- C:\Users\pc\Desktop\AlbumArtSmall.jpg
[2014.04.04 07:40:25 | 000,309,815 | ---- | M] () -- C:\Users\pc\Desktop\Pum HJ Desk and Pol - TechSpot Forums.htm
[2014.04.04 06:36:02 | 000,067,361 | ---- | M] () -- C:\Users\pc\Desktop\Remove Outdated Browser Detected pop-up virus (Removal Guide).htm
[2014.04.04 05:10:07 | 000,001,986 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2014.04.04 03:03:58 | 000,001,912 | ---- | M] () -- C:\windows\epplauncher.mif
[2014.04.03 23:41:27 | 000,000,492 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2014.04.03 21:20:38 | 000,987,448 | ---- | M] () -- C:\Users\pc\Desktop\SecurityCheck.exe
[2014.04.03 09:51:16 | 000,063,192 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mwac.sys
[2014.04.03 09:50:58 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2014.04.01 04:03:11 | 010,971,424 | ---- | M] (SurfRight B.V.) -- C:\Users\pc\Desktop\HitmanPro_x64.exe
[2014.04.01 03:38:14 | 000,430,608 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2014.04.01 03:31:00 | 000,050,826 | ---- | M] () -- C:\Users\pc\Desktop\Remove PWS-Zbot virus (Removal Instructions).htm
[2014.04.01 01:28:59 | 000,000,805 | ---- | M] () -- C:\windows\ScanSpyware.INI
[2014.03.31 23:55:40 | 004,233,347 | ---- | M] (ScanSpyware.Net ) -- C:\Users\pc\Desktop\ScanSpyware_3.9.2.2.exe
[2014.03.31 21:09:19 | 003,640,880 | ---- | M] () -- C:\Users\pc\Desktop\avg_remover_zbot.exe
[2014.03.30 01:00:41 | 000,000,002 | RHS- | M] () -- C:\windows\winstart.bat
[2014.03.30 01:00:41 | 000,000,002 | RHS- | M] () -- C:\windows\SysWow64\CONFIG.NT
[2014.03.30 01:00:41 | 000,000,002 | RHS- | M] () -- C:\windows\SysWow64\AUTOEXEC.NT
[2014.03.29 14:52:08 | 000,000,912 | ---- | M] () -- C:\Users\pc\Desktop\Ñîêğîâèùà Ìîíòåñóìû 3.lnk
[2014.03.29 13:00:35 | 000,430,026 | ---- | M] () -- C:\Users\pc\Desktop\3-66.jpg
[2014.03.29 05:41:06 | 000,002,184 | ---- | M] () -- C:\Users\pc\Desktop\Tales of Lagoona - Orphans of the Ocean.lnk
[2014.03.29 05:09:40 | 000,002,041 | ---- | M] () -- C:\Users\pc\Desktop\Saving Private Sheep.lnk
[2014.03.29 04:07:36 | 000,001,906 | ---- | M] () -- C:\Users\pc\Desktop\Mayan Puzzle.lnk
[2014.03.29 00:55:02 | 017,523,384 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\pc\Desktop\mbam-setup-2.0.0.1000 (1) - Kopya.exe
[2014.03.28 14:02:22 | 015,320,504 | ---- | M] (Greatis Software, LLC. ) -- C:\Users\pc\Desktop\unhackme_setup.exe
[2014.03.27 22:01:28 | 000,256,130 | ---- | M] () -- C:\Users\pc\Desktop\Trojan virus.. removed but still need help - TechSpot Forums.htm
[2014.03.27 01:07:59 | 000,001,343 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2014.03.26 03:23:57 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2014.03.19 16:17:47 | 002,451,517 | ---- | M] () -- C:\Users\pc\Desktop\1 mayis A Computer Based Discrimination Method for the Repetitive and Stochastic Defects on Fancy Yarns Based on Stochastic Signal Processing aOnarıldı).pdf
[2014.03.15 19:25:52 | 000,002,139 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
========== Files Created - No Company Name ==========
[2014.04.08 15:22:27 | 001,426,178 | ---- | C] () -- C:\Users\pc\Desktop\adwcleaner (1).exe
[2014.04.08 00:37:53 | 005,295,612 | ---- | C] () -- C:\Users\pc\Desktop\pisa 2012 Creative Problem Solving.pdf
[2014.04.06 22:23:47 | 003,972,608 | ---- | C] () -- C:\Users\pc\Desktop\RogueKiller.exe
[2014.04.06 02:18:53 | 000,050,078 | ---- | C] () -- C:\Users\pc\Desktop\Videos – Audioslides.htm
[2014.04.06 00:51:21 | 000,608,968 | ---- | C] () -- C:\Users\pc\Desktop\SignalProcessingofECGSignalsinMatlab.pdf
[2014.04.05 16:55:51 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014.04.05 06:56:17 | 000,043,703 | -HS- | C] () -- C:\Users\pc\Desktop\Folder.jpg
[2014.04.05 06:56:17 | 000,009,134 | -HS- | C] () -- C:\Users\pc\Desktop\AlbumArtSmall.jpg
[2014.04.04 07:40:20 | 000,309,815 | ---- | C] () -- C:\Users\pc\Desktop\Pum HJ Desk and Pol - TechSpot Forums.htm
[2014.04.04 06:35:54 | 000,067,361 | ---- | C] () -- C:\Users\pc\Desktop\Remove Outdated Browser Detected pop-up virus (Removal Guide).htm
[2014.04.03 21:20:49 | 000,987,448 | ---- | C] () -- C:\Users\pc\Desktop\SecurityCheck.exe
[2014.04.01 03:30:55 | 000,050,826 | ---- | C] () -- C:\Users\pc\Desktop\Remove PWS-Zbot virus (Removal Instructions).htm
[2014.04.01 01:38:24 | 000,001,912 | ---- | C] () -- C:\windows\epplauncher.mif
[2014.03.31 23:59:09 | 000,000,805 | ---- | C] () -- C:\windows\ScanSpyware.INI
[2014.03.31 21:09:08 | 003,640,880 | ---- | C] () -- C:\Users\pc\Desktop\avg_remover_zbot.exe
[2014.03.29 14:52:08 | 000,000,912 | ---- | C] () -- C:\Users\pc\Desktop\Ñîêğîâèùà Ìîíòåñóìû 3.lnk
[2014.03.29 05:41:06 | 000,002,184 | ---- | C] () -- C:\Users\pc\Desktop\Tales of Lagoona - Orphans of the Ocean.lnk
[2014.03.29 05:09:40 | 000,002,041 | ---- | C] () -- C:\Users\pc\Desktop\Saving Private Sheep.lnk
[2014.03.29 04:07:36 | 000,001,906 | ---- | C] () -- C:\Users\pc\Desktop\Mayan Puzzle.lnk
[2014.03.27 22:01:28 | 000,256,130 | ---- | C] () -- C:\Users\pc\Desktop\Trojan virus.. removed but still need help - TechSpot Forums.htm
[2014.03.27 06:11:11 | 000,430,026 | ---- | C] () -- C:\Users\pc\Desktop\3-66.jpg
[2014.03.27 05:13:07 | 000,177,043 | ---- | C] () -- C:\Users\pc\Desktop\111009-165400.jpg
[2014.03.27 05:12:46 | 000,168,697 | ---- | C] () -- C:\Users\pc\Desktop\111009-165302.jpg
[2014.03.27 01:07:59 | 000,001,355 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2014.03.27 01:07:59 | 000,001,343 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2014.03.26 22:55:56 | 000,256,000 | ---- | C] () -- C:\windows\PEV.exe
[2014.03.26 22:55:56 | 000,208,896 | ---- | C] () -- C:\windows\MBR.exe
[2014.03.26 22:55:56 | 000,098,816 | ---- | C] () -- C:\windows\sed.exe
[2014.03.26 22:55:56 | 000,080,412 | ---- | C] () -- C:\windows\grep.exe
[2014.03.26 22:55:56 | 000,068,096 | ---- | C] () -- C:\windows\zip.exe
[2014.03.26 05:33:24 | 000,000,002 | RHS- | C] () -- C:\windows\winstart.bat
[2014.03.26 05:33:24 | 000,000,002 | RHS- | C] () -- C:\windows\SysWow64\CONFIG.NT
[2014.03.26 05:33:24 | 000,000,002 | RHS- | C] () -- C:\windows\SysWow64\AUTOEXEC.NT
[2014.03.26 03:23:57 | 000,000,000 | ---- | C] () -- C:\autoexec.bat
[2014.03.19 16:17:47 | 002,451,517 | ---- | C] () -- C:\Users\pc\Desktop\1 mayis A Computer Based Discrimination Method for the Repetitive and Stochastic Defects on Fancy Yarns Based on Stochastic Signal Processing aOnarıldı).pdf
[2013.12.19 18:44:43 | 000,007,168 | ---- | C] () -- C:\Users\pc\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013.02.08 00:07:38 | 000,011,426 | ---- | C] () -- C:\Users\pc\gsview64.ini
[2012.09.04 10:19:30 | 000,000,162 | ---- | C] () -- C:\windows\ODBC.INI
[2012.09.01 03:04:15 | 000,650,752 | ---- | C] () -- C:\windows\SysWow64\xvidcore.dll
[2012.09.01 03:04:15 | 000,243,200 | ---- | C] () -- C:\windows\SysWow64\xvidvfw.dll
[2012.09.01 03:04:15 | 000,216,064 | ---- | C] ( ) -- C:\windows\SysWow64\lagarith.dll
[2012.09.01 03:04:13 | 000,178,688 | ---- | C] () -- C:\windows\SysWow64\unrar.dll
[2012.09.01 03:04:11 | 000,112,640 | ---- | C] () -- C:\windows\SysWow64\ff_vfw.dll
[2012.08.26 01:29:41 | 000,007,597 | ---- | C] () -- C:\Users\pc\AppData\Local\Resmon.ResmonCfg
[2012.08.24 13:14:40 | 001,546,540 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012.05.19 05:11:06 | 000,307,200 | ---- | C] () -- C:\windows\SetDisplayResolution.exe
[2012.05.19 04:45:59 | 000,003,226 | ---- | C] () -- C:\windows\HotFixList.ini
[2012.05.19 04:17:01 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2012.05.19 04:08:48 | 000,003,917 | ---- | C] () -- C:\windows\SysWow64\atipblup.dat
[2012.04.18 01:16:54 | 000,204,952 | ---- | C] () -- C:\windows\SysWow64\ativvsvl.dat
[2012.04.18 01:16:54 | 000,157,144 | ---- | C] () -- C:\windows\SysWow64\ativvsva.dat
[2012.04.18 01:14:24 | 000,054,784 | ---- | C] () -- C:\windows\SysWow64\OVDecode.dll
========== ZeroAccess Check ==========
[2009.07.14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.07.26 05:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.07.26 04:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 04:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.21 06:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 04:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013.04.01 15:41:07 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\IObit
[2013.04.01 15:41:07 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\IObit
[2013.12.28 02:14:08 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Audacity
[2014.03.29 05:25:57 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Boolat Games
[2013.04.09 06:13:16 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Boomzap
[2014.03.29 05:09:52 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\BULKYPIX
[2013.12.25 03:57:59 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Cakewalk
[2013.03.08 16:06:21 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Canon
[2012.08.28 11:07:42 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\ESET
[2012.09.15 16:36:48 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\FloodLightGames
[2013.04.08 17:11:56 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Friday's games
[2013.04.08 03:19:01 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Gogii Games
[2014.03.29 05:28:36 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\HdO Adventure
[2013.03.23 09:18:52 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\IObit
[2014.03.29 05:36:29 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\JQ
[2012.10.12 22:05:40 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\LogoDizayn
[2014.03.29 04:08:03 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Mayan Puzzle
[2012.10.08 17:23:33 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\MedCalc Software
[2014.03.29 13:05:33 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Meridian93
[2012.10.30 13:00:00 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\National Instruments
[2013.04.08 17:11:28 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Opera
[2014.03.30 02:00:00 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Picsoft
[2013.04.07 09:12:03 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\PlayFavoriteGames
[2013.04.09 20:45:49 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Playrix Entertainment
[2014.04.01 01:39:13 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\ScanSpyware
[2012.09.04 09:25:09 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\SoftGrid Client
[2014.03.30 02:21:06 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\TheFlyingDutchman
[2012.08.24 13:15:42 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\TP
[2013.05.10 14:34:27 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\webex
[2012.12.19 23:20:53 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Windows Live Writer
[2013.02.20 13:44:07 | 000,000,000 | ---D | M] -- C:\Users\pc\AppData\Roaming\Zbshareware Lab
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp

EE46C4E
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:2701988C
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:8AED9359
< End of report >