Şimdi Ara

Combofix rapor analizi konusunda yardım

Daha Fazla
Bu Konudaki Kullanıcılar: Daha Az
1 Misafir - 1 Masaüstü
5 sn
6
Cevap
0
Favori
668
Tıklama
Daha Fazla
İstatistik
  • Konu İstatistikleri Yükleniyor
0 oy
Öne Çıkar
Sayfa: 1
Giriş
Mesaj
  • ekde verdiğim raporu oluşturdu ilk defa bu işlemi yaptım garip olan normal taramalara göre çok daha hızlı normal bişey galiba 2 pc de denedim ama hiç bi sorunumu çözmedihttp://imgim.com/4342inciy2787181.png cpu ve bellek kullanımı sorunlarım var araştırdım ama pek bi sonuç bulamadım cpu kullanımı sanırsam ps2 girişli klavye kullanmamdan ama bellek kullanımı niye hala anlamış değilim svchost(localsystemnetworkrestricted) kullanıyo en çok rapor burda yardımcı olabilirseniz sevinirim


    ComboFix 15-01-08.01 - Usertr 10.01.2015 18:21:22.2.8 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1254.90.1055.18.4055.1867 [GMT 2:00]
    Running from: c:\users\Usertr\Desktop\ComboFix.exe
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\install.exe
    c:\program files (x86)\BrowserCompanion
    c:\program files (x86)\BrowserCompanion\blabbers-ch.crx
    c:\program files (x86)\BrowserCompanion\blabbers-ff-full.xpi
    c:\program files (x86)\BrowserCompanion\logo.ico
    c:\program files (x86)\BrowserCompanion\sqlite3.dll
    c:\program files (x86)\BrowserCompanion\toolbar.dll
    c:\program files (x86)\BrowserCompanion\uninstall.exe
    c:\program files (x86)\BrowserCompanion\updater.ini
    c:\program files (x86)\BrowserCompanion\widgetserv.exe
    c:\program files (x86)\Complitly
    c:\program files (x86)\Complitly\chrome\ComplitlyChrome.crx
    c:\program files (x86)\Complitly\FireFoxExtensionWithFF8Fix.exe
    c:\program files (x86)\Complitly\FireFoxUninstaller.exe
    c:\program files (x86)\Complitly\InstTracker.exe
    c:\program files (x86)\Complitly\support@Complitly.com\chrome.manifest
    c:\program files (x86)\Complitly\support@Complitly.com\chrome\content\appIcon.png
    c:\program files (x86)\Complitly\support@Complitly.com\chrome\content\browserOverlay.xul
    c:\program files (x86)\Complitly\support@Complitly.com\chrome\content\options.js
    c:\program files (x86)\Complitly\support@Complitly.com\chrome\content\options.xul
    c:\program files (x86)\Complitly\support@Complitly.com\chrome\content\utils.js
    c:\program files (x86)\Complitly\support@Complitly.com\defaults\preferences\predictad.js
    c:\program files (x86)\Complitly\support@Complitly.com\install.rdf
    c:\program files (x86)\Complitly\System.Data.SQLite.dll
    c:\program files (x86)\Complitly\unins000.dat
    c:\program files (x86)\Complitly\unins000.exe
    c:\program files (x86)\sXe Injected
    c:\program files (x86)\sXe Injected\ddsxei.sys
    c:\program files (x86)\sXe Injected\sXe-I EULA.txt
    c:\program files (x86)\sXe Injected\sXe Injected.exe
    c:\program files (x86)\sXe Injected\sXe Injected.txt
    c:\program files (x86)\sXe Injected\sXe.dll
    c:\program files (x86)\sXe Injected\uninstall.exe
    c:\program files (x86)\sXe Injected\uninstall.ini
    c:\programdata\1393362323.bdinstall.bin
    c:\programdata\1401376342.bdinstall.bin
    c:\users\Usertr\AppData\Roaming\Complitly
    c:\users\Usertr\AppData\Roaming\Complitly\64\Complitly64.dll
    c:\users\Usertr\AppData\Roaming\Complitly\64\KeepMeUpdated.exe
    c:\users\Usertr\AppData\Roaming\Complitly\Complitly.dll
    c:\users\Usertr\AppData\Roaming\Complitly\KeepMeUpdated.exe
    c:\users\Usertr\AppData\Roaming\IHelper
    c:\windows\msdownld.tmp
    c:\windows\SysWow64\SET5F05.tmp
    c:\windows\SysWow64\SET7536.tmp
    c:\windows\SysWow64\SET980D.tmp
    c:\windows\SysWow64\SET9E00.tmp
    c:\windows\TEMP\logishrd\LVPrcInj01.dll . . . . Failed to delete
    c:\windows\TEMP\logishrd\LVPrcInj02.dll . . . . Failed to delete
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Service_sed
    .
    .
    ((((((((((((((((((((((((( Files Created from 2014-12-10 to 2015-01-10 )))))))))))))))))))))))))))))))
    .
    .
    2015-01-10 16:30 . 2015-01-10 16:30 -------- d-----w- c:\users\Default\AppData\Local\temp
    2015-01-05 18:02 . 2015-01-05 18:02 165888 ----a-w- c:\windows\system32\charmap.exe
    2015-01-05 18:02 . 2015-01-05 18:02 155136 ----a-w- c:\windows\SysWow64\charmap.exe
    2015-01-05 18:00 . 2015-01-05 18:00 2048 ----a-w- c:\windows\system32\tzres.dll
    2015-01-05 17:58 . 2015-01-05 17:58 119296 ----a-w- c:\windows\system32\drivers\tdx.sys
    2015-01-05 17:58 . 2015-01-05 17:58 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
    2014-12-31 12:53 . 2012-10-13 05:08 165952 ----a-w- c:\windows\system32\drivers\Impcd.sys
    2014-12-31 12:53 . 2012-10-13 05:08 67392 ----a-w- c:\windows\system32\drivers\EtmDevPch.sys
    2014-12-31 12:06 . 2014-12-31 12:06 -------- d-----w- c:\users\Usertr\AppData\Roaming\Innovative Solutions
    2014-12-20 18:06 . 2014-12-20 18:06 -------- d-----w- c:\programdata\ATI
    2014-12-20 18:04 . 2014-12-20 18:04 -------- d-----w- c:\program files (x86)\AMD AVT
    2014-12-11 18:00 . 2014-12-11 18:00 33008 ----a-w- c:\windows\system32\drivers\Smb_driver_Intel.sys
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2015-01-06 02:36 . 2012-08-24 13:15 298120 ------w- c:\windows\system32\MpSigStub.exe
    2015-01-05 18:04 . 2015-01-05 18:04 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb
    2015-01-05 18:04 . 2015-01-05 18:04 1155072 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
    2015-01-05 18:04 . 2015-01-05 18:04 501248 ----a-w- c:\windows\SysWow64\vbscript.dll
    2015-01-05 18:04 . 2015-01-05 18:04 1888256 ----a-w- c:\windows\SysWow64\wininet.dll
    2015-01-05 18:04 . 2015-01-05 18:04 64000 ----a-w- c:\windows\SysWow64\MshtmlDac.dll
    2015-01-05 18:01 . 2015-01-05 18:01 248832 ----a-w- c:\windows\SysWow64\WSManMigrationPlugin.dll
    2015-01-05 18:01 . 2015-01-05 18:01 198656 ----a-w- c:\windows\SysWow64\WSManHTTPConfig.exe
    2015-01-05 18:01 . 2015-01-05 18:01 145920 ----a-w- c:\windows\SysWow64\WsmAuto.dll
    2015-01-05 18:01 . 2015-01-05 18:01 1177088 ----a-w- c:\windows\SysWow64\WsmSvc.dll
    2015-01-05 18:01 . 2015-01-05 18:01 214016 ----a-w- c:\windows\SysWow64\WsmWmiPl.dll
    2015-01-05 18:01 . 2015-01-05 18:01 50176 ----a-w- c:\windows\SysWow64\rrinstaller.exe
    2015-01-05 18:00 . 2015-01-05 18:00 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    2015-01-05 17:58 . 2015-01-05 17:58 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
    2014-12-29 17:05 . 2012-08-29 10:54 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
    2014-12-29 17:05 . 2012-08-23 12:14 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
    2014-12-13 00:20 . 2014-12-13 00:20 119808 ----a-r- c:\users\Usertr\AppData\Roaming\Microsoft\Installer\{CCF298AF-9CE1-4B26-B251-486E98A34789}\icons.exe
    2014-12-02 10:26 . 2015-01-10 00:15 11870360 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DEF25183-55A6-46CC-8EF6-382E544B8D7E}\mpengine.dll
    2014-11-30 18:19 . 2012-08-24 14:48 103374192 ----a-w- c:\windows\system32\MRT.exe
    2014-11-21 02:44 . 2014-11-21 02:44 78432 ----a-w- c:\windows\system32\atimpc64.dll
    2014-11-21 02:44 . 2014-11-21 02:44 78432 ----a-w- c:\windows\system32\amdpcom64.dll
    2014-11-21 02:44 . 2014-11-21 02:44 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll
    2014-11-21 02:44 . 2014-11-21 02:44 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll
    2014-11-21 02:44 . 2010-10-27 02:20 144328 ----a-w- c:\windows\system32\atiuxp64.dll
    2014-11-21 02:44 . 2014-09-15 22:31 126848 ----a-w- c:\windows\SysWow64\atiuxpag.dll
    2014-11-21 02:44 . 2013-10-08 14:01 118096 ----a-w- c:\windows\system32\atiu9p64.dll
    2014-11-21 02:44 . 2014-11-21 02:44 100032 ----a-w- c:\windows\SysWow64\atiu9pag.dll
    2014-11-21 02:44 . 2010-10-27 02:24 1348928 ----a-w- c:\windows\system32\aticfx64.dll
    2014-11-21 02:44 . 2010-10-27 02:24 1127496 ----a-w- c:\windows\SysWow64\aticfx32.dll
    2014-11-21 02:44 . 2010-10-27 02:23 11076784 ----a-w- c:\windows\system32\atidxx64.dll
    2014-11-21 02:44 . 2014-09-15 22:31 9401480 ----a-w- c:\windows\SysWow64\atidxx32.dll
    2014-11-21 02:43 . 2014-11-21 02:43 7558816 ----a-w- c:\windows\SysWow64\atiumdva.dll
    2014-11-21 02:43 . 2014-11-21 02:43 7077776 ----a-w- c:\windows\SysWow64\atiumdag.dll
    2014-11-21 02:43 . 2013-10-08 14:00 8379720 ----a-w- c:\windows\system32\atiumd6a.dll
    2014-11-21 02:43 . 2013-10-08 14:00 8369408 ----a-w- c:\windows\system32\atiumd64.dll
    2014-11-21 02:41 . 2014-11-21 02:41 294600 ----a-w- c:\windows\system32\drivers\amdacpksd.sys
    2014-11-21 02:40 . 2014-11-21 02:40 18959360 ----a-w- c:\windows\system32\drivers\atikmdag.sys
    2014-11-21 02:33 . 2014-11-21 02:33 235008 ----a-w- c:\windows\system32\clinfo.exe
    2014-11-21 02:33 . 2014-11-21 02:33 98816 ----a-w- c:\windows\system32\OpenVideo64.dll
    2014-11-21 02:33 . 2014-11-21 02:33 83456 ----a-w- c:\windows\SysWow64\OpenVideo.dll
    2014-11-21 02:33 . 2014-11-21 02:33 86528 ----a-w- c:\windows\system32\OVDecode64.dll
    2014-11-21 02:33 . 2014-11-21 02:33 73216 ----a-w- c:\windows\SysWow64\OVDecode.dll
    2014-11-21 02:33 . 2014-11-21 02:33 47899136 ----a-w- c:\windows\system32\amdocl64.dll
    2014-11-21 02:32 . 2014-11-21 02:32 40987136 ----a-w- c:\windows\SysWow64\amdocl.dll
    2014-11-21 02:31 . 2014-11-21 02:31 65024 ----a-w- c:\windows\system32\OpenCL.dll
    2014-11-21 02:31 . 2014-11-21 02:31 58880 ----a-w- c:\windows\SysWow64\OpenCL.dll
    2014-11-21 02:24 . 2014-11-21 02:24 28354560 ----a-w- c:\windows\system32\atio6axx.dll
    2014-11-21 02:19 . 2014-11-21 02:19 23621632 ----a-w- c:\windows\SysWow64\atioglxx.dll
    2014-11-21 02:19 . 2014-11-21 02:19 49664 ----a-w- c:\windows\system32\amdmmcl6.dll
    2014-11-21 02:19 . 2014-11-21 02:19 38912 ----a-w- c:\windows\SysWow64\amdmmcl.dll
    2014-11-21 02:18 . 2014-11-21 02:18 127488 ----a-w- c:\windows\system32\mantle64.dll
    2014-11-21 02:18 . 2014-11-21 02:18 113664 ----a-w- c:\windows\SysWow64\mantle32.dll
    2014-11-21 02:18 . 2014-11-21 02:18 5837312 ----a-w- c:\windows\system32\amdmantle64.dll
    2014-11-21 02:17 . 2014-11-21 02:17 367104 ----a-w- c:\windows\system32\atiapfxx.exe
    2014-11-21 02:17 . 2014-11-21 02:17 62464 ----a-w- c:\windows\system32\aticalrt64.dll
    2014-11-21 02:17 . 2014-11-21 02:17 52224 ----a-w- c:\windows\SysWow64\aticalrt.dll
    2014-11-21 02:16 . 2014-11-21 02:16 55808 ----a-w- c:\windows\system32\aticalcl64.dll
    2014-11-21 02:16 . 2014-11-21 02:16 49152 ----a-w- c:\windows\SysWow64\aticalcl.dll
    2014-11-21 02:16 . 2014-11-21 02:16 15716352 ----a-w- c:\windows\system32\aticaldd64.dll
    2014-11-21 02:16 . 2014-11-21 02:16 14302208 ----a-w- c:\windows\SysWow64\aticaldd.dll
    2014-11-21 02:15 . 2014-11-21 02:15 4590592 ----a-w- c:\windows\SysWow64\amdmantle32.dll
    2014-11-21 02:13 . 2014-11-21 02:13 91648 ----a-w- c:\windows\system32\mantleaxl64.dll
    2014-11-21 02:13 . 2014-11-21 02:13 85504 ----a-w- c:\windows\SysWow64\mantleaxl32.dll
    2014-11-21 02:12 . 2014-11-21 02:12 31232 ----a-w- c:\windows\system32\atimuixx.dll
    2014-11-21 02:12 . 2013-10-08 12:54 442368 ----a-w- c:\windows\system32\atidemgy.dll
    2014-11-21 02:12 . 2014-11-21 02:12 774656 ----a-w- c:\windows\system32\atieclxx.exe
    2014-11-21 02:12 . 2014-11-21 02:12 244736 ----a-w- c:\windows\system32\atiesrxx.exe
    2014-11-21 02:12 . 2014-11-21 02:12 190976 ----a-w- c:\windows\system32\atitmm64.dll
    2014-11-21 02:10 . 2014-11-21 02:10 843776 ----a-w- c:\windows\system32\coinst_14.50.dll
    2014-11-21 02:09 . 2013-10-08 12:28 1214976 ----a-w- c:\windows\system32\atiadlxx.dll
    2014-11-21 02:09 . 2014-10-04 18:31 903168 ----a-w- c:\windows\SysWow64\atiadlxy.dll
    2014-11-21 02:09 . 2014-11-21 02:09 75264 ----a-w- c:\windows\system32\atig6pxx.dll
    2014-11-21 02:09 . 2014-11-21 02:09 69632 ----a-w- c:\windows\SysWow64\atiglpxx.dll
    2014-11-21 02:09 . 2014-11-21 02:09 69632 ----a-w- c:\windows\system32\atiglpxx.dll
    2014-11-21 02:08 . 2014-11-21 02:08 146944 ----a-w- c:\windows\system32\atig6txx.dll
    2014-11-21 02:08 . 2014-11-21 02:08 133632 ----a-w- c:\windows\SysWow64\atigktxx.dll
    2014-11-21 02:08 . 2014-11-21 02:08 589312 ----a-w- c:\windows\system32\drivers\atikmpag.sys
    2014-11-21 02:08 . 2014-11-21 02:08 43520 ----a-w- c:\windows\system32\drivers\ati2erec.dll
    2014-11-20 19:36 . 2014-11-20 19:36 51200 ----a-w- c:\windows\system32\kdbsdk64.dll
    2014-11-20 19:35 . 2014-11-20 19:35 38912 ----a-w- c:\windows\SysWow64\kdbsdk32.dll
    2014-11-14 20:05 . 2014-11-14 20:05 3241984 ----a-w- c:\windows\system32\msi.dll
    2014-11-14 20:05 . 2014-11-14 20:05 2363904 ----a-w- c:\windows\SysWow64\msi.dll
    2014-11-14 20:03 . 2014-11-14 20:03 2048 ----a-w- c:\windows\SysWow64\msxml3r.dll
    2014-11-14 20:03 . 2014-11-14 20:03 2048 ----a-w- c:\windows\system32\msxml3r.dll
    2014-11-14 20:03 . 2014-11-14 20:03 1882624 ----a-w- c:\windows\system32\msxml3.dll
    2014-11-14 20:03 . 2014-11-14 20:03 1237504 ----a-w- c:\windows\SysWow64\msxml3.dll
    2014-11-14 20:02 . 2014-11-14 20:02 683520 ----a-w- c:\windows\system32\termsrv.dll
    2014-11-14 20:02 . 2014-11-14 20:02 681984 ----a-w- c:\windows\system32\adtschema.dll
    2014-11-14 20:02 . 2014-11-14 20:02 155064 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
    2014-11-14 20:02 . 2014-11-14 20:02 146432 ----a-w- c:\windows\system32\msaudite.dll
    2014-11-14 20:02 . 2014-11-14 20:02 1460736 ----a-w- c:\windows\system32\lsasrv.dll
    2014-11-14 20:02 . 2014-11-14 20:02 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
    2014-11-14 20:02 . 2014-11-14 20:02 681984 ----a-w- c:\windows\SysWow64\adtschema.dll
    2014-11-14 20:02 . 2014-11-14 20:02 22016 ----a-w- c:\windows\SysWow64\secur32.dll
    2014-11-14 20:02 . 2014-11-14 20:02 146432 ----a-w- c:\windows\SysWow64\msaudite.dll
    2014-11-14 19:59 . 2014-11-14 19:59 3198976 ----a-w- c:\windows\system32\win32k.sys
    2014-11-14 19:58 . 2014-11-14 19:58 77824 ----a-w- c:\windows\system32\packager.dll
    2014-11-14 19:58 . 2014-11-14 19:58 67584 ----a-w- c:\windows\SysWow64\packager.dll
    2014-11-14 19:57 . 2014-11-14 19:57 861696 ----a-w- c:\windows\system32\oleaut32.dll
    2014-11-14 19:57 . 2014-11-14 19:57 571904 ----a-w- c:\windows\SysWow64\oleaut32.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{9D974C8C-6D92-44FB-BEAF-B45A1C0CF17F}]
    2014-06-11 13:20 464720 ----a-w- c:\program files (x86)\IObit\IObit Malware Fighter\adsremoval\IE\****.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
    @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
    [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
    2013-08-14 13:39 222832 ----a-w- c:\users\Usertr\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
    @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
    [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
    2013-08-14 13:39 222832 ----a-w- c:\users\Usertr\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
    @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
    [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
    2013-08-14 13:39 222832 ----a-w- c:\users\Usertr\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\SkyDriveShell.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 131480 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 131480 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
    @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 131480 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
    @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 131480 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 131480 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
    @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 131480 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 131480 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
    @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 131480 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "IObit Malware Fighter"="c:\program files (x86)\IObit\IObit Malware Fighter\IMF.exe" [2014-10-13 1802048]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2014-12-19 1022152]
    "StartCCC"="c:\program files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2014-11-20 767176]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Autodesk Sync"="c:\program files\Autodesk\Autodesk Sync\AdSync.exe" [2013-02-04 1081224]
    "Advanced SystemCare 8"="c:\program files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe" [2014-11-25 2426144]
    .
    c:\users\Usertr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    Dropbox.lnk - c:\users\Usertr\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-12-9 39207112]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
    "LoadAppInit_DLLs"=1 (0x1)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
    @="Service"
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "UpdatesDisableNotify"=dword:00000001
    .
    R2 BstHdAndroidSvc;BlueStacks Android Service;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android;c:\program files (x86)\BlueStacks\HD-Service.exe BstHdAndroidSvc Android [x]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
    R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe;c:\program files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe [x]
    R2 LiveUpdateSvc;LiveUpdate;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe;c:\program files (x86)\IObit\LiveUpdate\LiveUpdate.exe [x]
    R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
    R3 ALSysIO;ALSysIO; [x]
    R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x]
    R3 aswTap;avast! SecureLine TAP Adapter v3;c:\windows\system32\DRIVERS\aswTap.sys;c:\windows\SYSNATIVE\DRIVERS\aswTap.sys [x]
    R3 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x]
    R3 awUSB;awUSB;c:\windows\system32\DRIVERS\USBDrv_AMD64.sys;c:\windows\SYSNATIVE\DRIVERS\USBDrv_AMD64.sys [x]
    R3 BlackBerry Device Manager;BlackBerry Device Manager;c:\program files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe;c:\program files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [x]
    R3 BRDriver64;BRDriver64; [x]
    R3 BRSptSvc;BitRaider Mini-Support Service;c:\programdata\BitRaider\BRSptSvc.exe;c:\programdata\BitRaider\BRSptSvc.exe [x]
    R3 BstHdLogRotatorSvc;BlueStacks Log Rotator Service;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe;c:\program files (x86)\BlueStacks\HD-LogRotatorService.exe [x]
    R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x]
    R3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys;c:\windows\SYSNATIVE\drivers\dgderdrv.sys [x]
    R3 EagleX64;EagleX64; [x]
    R3 EtmDevPch;EtmDevPch;c:\windows\system32\DRIVERS\EtmDevPch.sys;c:\windows\SYSNATIVE\DRIVERS\EtmDevPch.sys [x]
    R3 FlexNet Licensing Service 64;FlexNet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
    R3 FsUsbExDisk;FsUsbExDisk;c:\windows\SysWOW64\FsUsbExDisk.SYS;c:\windows\SysWOW64\FsUsbExDisk.SYS [x]
    R3 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
    R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
    R3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x]
    R3 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe;c:\program files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [x]
    R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys;c:\windows\SYSNATIVE\DRIVERS\netaapl64.sys [x]
    R3 Origin Client Service;Origin Client Service;c:\program files (x86)\Origin\OriginClientService.exe;c:\program files (x86)\Origin\OriginClientService.exe [x]
    R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
    R3 pneteth;PdaNet Broadband;c:\windows\system32\DRIVERS\pneteth.sys;c:\windows\SYSNATIVE\DRIVERS\pneteth.sys [x]
    R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
    R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys;c:\windows\SYSNATIVE\DRIVERS\revoflt.sys [x]
    R3 SamsungAllShareV2.0;Samsung AllShare PC;c:\program files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe;c:\program files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe [x]
    R3 SimpleSlideShowServer;SimpleSlideShowServer;c:\program files (x86)\Samsung\AllShare\AllShareSlideShowService.exe;c:\program files (x86)\Samsung\AllShare\AllShareSlideShowService.exe [x]
    R3 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
    R3 Sony PC Companion;Sony PC Companion;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe;c:\program files (x86)\Sony\Sony PC Companion\PCCService.exe [x]
    R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x]
    R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x]
    R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x]
    R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x]
    R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x]
    R3 ssudobex;SAMSUNG Mobile USB OBEX Serial Port(DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudobex.sys;c:\windows\SYSNATIVE\DRIVERS\ssudobex.sys [x]
    R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
    R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys;c:\windows\SYSNATIVE\DRIVERS\taphss6.sys [x]
    R3 tapSF0901;Spotflux Virtual Network Device Driver;c:\windows\system32\DRIVERS\tapSF0901.sys;c:\windows\SYSNATIVE\DRIVERS\tapSF0901.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
    R3 usbUDisc;usbUDisc;c:\windows\system32\DRIVERS\USBDrv_AMD64.sys;c:\windows\SYSNATIVE\DRIVERS\USBDrv_AMD64.sys [x]
    R3 WatAdminSvc;Windows Etkinleştirme Teknolojileri Hizmeti;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
    R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys;c:\program files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [x]
    R3 wolf;wolf;c:\program files (x86)\Joygame\WolfTeamTS\avital\wolf64.sys;c:\program files (x86)\Joygame\WolfTeamTS\avital\wolf64.sys [x]
    S0 SmartDefragDriver;SmartDefragDriver;c:\windows\System32\Drivers\SmartDefragDriver.sys;c:\windows\SYSNATIVE\Drivers\SmartDefragDriver.sys [x]
    S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
    S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxDrv.sys [x]
    S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxUSBMon.sys [x]
    S2 AdvancedSystemCareService8;Advanced SystemCare Service 8;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe;c:\program files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [x]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
    S2 BstHdDrv;BlueStacks Hypervisor;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys;c:\program files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [x]
    S2 BstHdUpdaterSvc;BlueStacks Updater Service;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe;c:\program files (x86)\BlueStacks\HD-UpdaterService.exe [x]
    S2 game assistant by-pass UAC;game assistant by-pass UAC;c:\program files (x86)\IObit\Game Assistant\gatsvc.exe;c:\program files (x86)\IObit\Game Assistant\gatsvc.exe [x]
    S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys;c:\windows\SYSNATIVE\DRIVERS\idmwfp.sys [x]
    S2 IMFservice;IMF Service;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe;c:\program files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [x]
    S2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [x]
    S2 NTServiceSystem;NTServiceSystem;c:\windows\SysWOW64\NTServer\service.exe;c:\windows\SysWOW64\NTServer\service.exe [x]
    S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
    S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
    S3 cpuz138;cpuz138;c:\windows\TEMP\cpuz138\cpuz138_x64.sys;c:\windows\TEMP\cpuz138\cpuz138_x64.sys [x]
    S3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\DRIVERS\dc3d.sys;c:\windows\SYSNATIVE\DRIVERS\dc3d.sys [x]
    S3 FileMonitor;FileMonitor;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys;c:\program files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [x]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
    S3 lvpepf64;Volume Adapter;c:\windows\system32\DRIVERS\lv302a64.sys;c:\windows\SYSNATIVE\DRIVERS\lv302a64.sys [x]
    S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x]
    S3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
    S3 LVUSBS64;Logitech USB Monitor Filter;c:\windows\system32\drivers\LVUSBS64.sys;c:\windows\SYSNATIVE\drivers\LVUSBS64.sys [x]
    S3 MonitorFunction;Driver for Monitor;c:\windows\system32\DRIVERS\TVMonitor.sys;c:\windows\SYSNATIVE\DRIVERS\TVMonitor.sys [x]
    S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys;c:\windows\SYSNATIVE\DRIVERS\point64.sys [x]
    S3 RegFilter;RegFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
    S3 SmbDrvI;SmbDrvI;c:\windows\system32\DRIVERS\Smb_driver_Intel.sys;c:\windows\SYSNATIVE\DRIVERS\Smb_driver_Intel.sys [x]
    S3 UrlFilter;UrlFilter;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys;c:\program files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\UrlFilter.sys [x]
    S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x]
    .
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2014-12-26 c:\windows\Tasks\Adobe Acrobat Update Task.job
    - c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19 06:48]
    .
    2015-01-10 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-29 17:05]
    .
    2014-12-11 c:\windows\Tasks\Driver Booster Scan.job
    - c:\program files (x86)\IObit\Driver Booster\Scheduler.exe [2014-11-11 13:52]
    .
    2014-12-11 c:\windows\Tasks\Driver Booster SkipUAC (Usertr).job
    - c:\program files (x86)\IObit\Driver Booster\DriverBooster.exe [2014-11-11 14:11]
    .
    2014-12-11 c:\windows\Tasks\Driver Booster Update.job
    - c:\program files (x86)\IObit\Driver Booster\AutoUpdate.exe [2014-11-11 14:17]
    .
    2013-03-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1564830312-1083165729-2531934164-1000Core1ce1ffa827f947c.job
    - c:\users\Usertr\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-19 14:53]
    .
    2013-10-13 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1564830312-1083165729-2531934164-1000UA.job
    - c:\users\Usertr\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-09-19 14:53]
    .
    2014-10-21 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cf90acb9910b79.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-26 21:21]
    .
    2014-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cfed559af33ac1.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-26 21:21]
    .
    2014-11-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d0012dc5bbd8c1.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-26 21:21]
    .
    2013-10-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-26 21:21]
    .
    2014-11-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1564830312-1083165729-2531934164-1000Core1cf8fbb578fe075.job
    - c:\users\Usertr\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-24 13:07]
    .
    2014-11-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1564830312-1083165729-2531934164-1000Core1d0075dd1e9b4d.job
    - c:\users\Usertr\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-24 13:07]
    .
    2013-10-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1564830312-1083165729-2531934164-1000UA.job
    - c:\users\Usertr\AppData\Local\Google\Update\GoogleUpdate.exe [2012-08-24 13:07]
    .
    2013-07-03 c:\windows\Tasks\Norton Security Scan for Usertr.job
    - c:\progra~2\NORTON~2\Engine\401~1.16\Nss.exe [2013-07-03 12:59]
    .
    2014-12-17 c:\windows\Tasks\Opera scheduled Autoupdate 1413489464.job
    - c:\program files (x86)\Opera\launcher.exe [2014-10-16 08:50]
    .
    2013-11-05 c:\windows\Tasks\SomotoUpdateCheckerAutoStart.job
    - c:\users\Usertr\AppData\Local\FilesFrog Update Checker\update_checker.exe [2013-10-17 09:50]
    .
    2014-11-09 c:\windows\Tasks\Uninstaller_SkipUac_Administrator.job
    - c:\program files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-11-09 15:35]
    .
    2015-01-10 c:\windows\Tasks\Uninstaller_SkipUac_Usertr.job
    - c:\program files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2014-11-09 15:35]
    .
    2013-11-15 c:\windows\Tasks\{62C67DC9-418D-41B9-9D32-CBF69BF7C9F1}.job
    - c:\program files (x86)\mozilla firefox\firefox.exe [2014-07-31 16:10]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814}]
    2014-12-11 14:54 2471744 ----a-w- c:\program files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive1]
    @="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
    [HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
    2013-08-14 13:38 261744 ----a-w- c:\users\Usertr\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive2]
    @="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
    [HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
    2013-08-14 13:38 261744 ----a-w- c:\users\Usertr\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ SkyDrive3]
    @="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
    [HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
    2013-08-14 13:38 261744 ----a-w- c:\users\Usertr\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64\SkyDriveShell64.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt1"]
    @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 164760 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt2"]
    @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 164760 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt3"]
    @="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 164760 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt4"]
    @="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 164760 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt5"]
    @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 164760 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt6"]
    @="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 164760 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt7"]
    @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 164760 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\"DropboxExt8"]
    @="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
    [HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
    2014-06-24 22:04 164760 ----a-w- c:\users\Usertr\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
    @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
    [HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
    2012-02-08 00:49 23432 ----a-w- c:\program files (x86)\Internet Download Manager\IDMShellExt64.dll
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2014-11-11 13672152]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uDefault_Search_URL = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=smt&utm_campaign=rg&utm_content=ds&from=smt&uid=SAMSUNGXHD105SI_S25GJ9AB101732&ts=1383679056&type=default&q={searchTerms}
    uStart Page = google.com
    mDefault_Search_URL = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=smt&utm_campaign=rg&utm_content=ds&from=smt&uid=SAMSUNGXHD105SI_S25GJ9AB101732&ts=1383679056&type=default&q={searchTerms}
    mDefault_Page_URL = about:blank
    mStart Page = about:blank
    mLocal Page = c:\windows\SysWOW64\blank.htm
    mSearch Page = hxxp://search.dosearches.com/web/?utm_source=b&utm_medium=smt&utm_campaign=rg&utm_content=ds&from=smt&uid=SAMSUNGXHD105SI_S25GJ9AB101732&ts=1383679056&type=default&q={searchTerms}
    uInternet Settings,ProxyOverride = *.local
    IE: Bütün linkleri IDM ile indir - c:\program files (x86)\Internet Download Manager\IEGetAll.htm
    IE: IDM ile indir - c:\program files (x86)\Internet Download Manager\IEExt.htm
    IE: Microsoft Excel'e &Ver - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: OneNote'a G&önder - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    TCP: Interfaces\{B97FA820-3940-45CA-8A60-D79017A86CE6}: NameServer = 8.8.8.8,8.8.4.4
    TCP: Interfaces\{D83A5251-F64E-4412-90CD-20E6A2102903}: NameServer = 4.2.2.4,4.2.2.6
    FF - ProfilePath - c:\users\Usertr\AppData\Roaming\Mozilla\Firefox\Profiles\1qvf6ubm.default\
    FF - prefs.js: browser.search.defaulturl -
    FF - prefs.js: keyword.URL -
    FF - ExtSQL: 2014-11-12 22:05; iobitapps@mybrowserbar.com; c:\program files (x86)\IObit Apps Toolbar\FF
    FF - ExtSQL: !HIDDEN! 2012-08-30 14:45; smartwebprinting@hp.com; c:\program files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
    FF - user.js: network.http.pipelining.maxrequests - 8
    FF - user.js: network.http.request.max-start-delay - 0
    FF - user.js: network.http.max-connections - 48
    FF - user.js: network.http.max-connections-per-server - 16
    FF - user.js: network.http.max-persistent-connections-per-proxy - 16
    FF - user.js: network.http.max-persistent-connections-per-server - 8
    FF - user.js: browser.turbo.enabled - true
    FF - user.js: browser.display.show_image_placeholders - true
    FF - user.js: browser.chrome.favicons - false
    FF - user.js: browser.urlbar.autocomplete.enabled - true
    FF - user.js: browser.cache.memory.capacity - 65536
    FF - user.js: content.notify.ontimer - true
    FF - user.js: content.interrupt.parsing - true
    FF - user.js: content.max.tokenizing.time - 2250000
    FF - user.js: content.switch.threshold - 750000
    FF - user.js: plugin.expose_full_path - true
    FF - user.js: ui.submenuDelay - 0
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Wow6432Node-HKCU-Run-AdobeBridge - (no file)
    HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
    ShellIconOverlayIdentifiers-{472083B0-C522-11CF-8763-00608CC02F24} - (no file)
    HKLM-Run-egui - c:\program files\ESET\ESET NOD32 Antivirus\egui.exe
    AddRemove-BrowserCompanion - c:\program files (x86)\BrowserCompanion\uninstall.exe
    AddRemove-sXe Injected - c:\program files (x86)\sXe Injected\uninstall.exe
    AddRemove-{4FFBB818-B13C-11E0-931D-B2664824019B}_is1 - c:\program files (x86)\Complitly\unins000.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1564830312-1083165729-2531934164-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.Email.1"
    .
    [HKEY_USERS\S-1-5-21-1564830312-1083165729-2531934164-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.VCard.1"
    .
    [HKEY_USERS\S-1-5-21-1564830312-1083165729-2531934164-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
    "??"=hex:8e,73,c5,02,9a,44,0e,e7,66,71,fd,d2,3f,83,a7,91,bb,8a,1f,a5,3b,de,cd,
    ef,bb,18,00,5a,b4,87,6c,34,72,d9,60,10,58,75,ac,ab,61,b8,5c,0c,13,99,e1,e0,\
    "??"=hex:9e,07,c1,21,02,50,c8,a8,db,b9,ea,68,70,c2,bb,72
    .
    [HKEY_USERS\S-1-5-21-1564830312-1083165729-2531934164-1000\Software\SecuROM\License information*]
    "datasecu"=hex:b6,80,65,28,00,1c,91,69,d0,dc,cc,d1,ee,73,99,c8,ce,e3,e8,99,6c,
    f8,aa,39,11,98,b8,c7,00,1d,fb,64,e3,4e,e7,f0,7d,94,f6,18,1d,e8,cb,1a,52,6f,\
    "rkeysecu"=hex:8c,c7,46,27,9b,64,48,cd,dd,44,fb,05,84,9d,45,68
    .
    [HKEY_USERS\S-1-5-21-1564830312-1083165729-2531934164-1000_Classes\Wow6432Node\CLSID\{3ab284a8-d74d-4dac-9f6a-f9c95089c7a9}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "Model"=dword:00000168
    "Therad"=dword:0000001a
    "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
    38,95,44,54,8d,98,e5,c2,04,0d,8b,7d,c2,18,1a,0e,79,3a,97,d9,dd,d0,a2,be,bc,\
    .
    [HKEY_USERS\S-1-5-21-1564830312-1083165729-2531934164-1000_Classes\Wow6432Node\CLSID\{570248f1-08cc-4206-90a2-7246436bc2d7}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "Model"=dword:00000107
    "Therad"=dword:00000016
    .
    [HKEY_USERS\S-1-5-21-1564830312-1083165729-2531934164-1000_Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "scansk"=hex(0):c6,f9,de,74,23,22,30,94,07,da,37,f5,a2,46,79,54,52,b5,c2,80,3f,
    5b,0b,68,23,39,a5,be,91,41,3c,32,cc,12,a3,05,a6,c0,80,91,00,00,00,00,00,00,\
    .
    [HKEY_USERS\S-1-5-21-1564830312-1083165729-2531934164-1000_Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "scansk"=hex(0):c7,d8,37,b2,0d,76,34,aa,5b,a6,0b,bf,1c,66,f0,06,92,6d,0b,46,57,
    6b,0e,3f,a8,b7,76,a7,c3,09,24,b9,7c,42,a1,c3,92,41,26,7c,00,00,00,00,00,00,\
    .
    [HKEY_LOCAL_MACHINE\software\BlueStacks]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_223_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
    @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_15_0_0_223_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker6"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_223_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_15_0_0_223_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_223.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.15"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_223.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_223.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_15_0_0_223.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker6"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
    c:\program files (x86)\IObit\Game Assistant\hdtmonitor.exe
    c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    c:\program files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
    c:\program files (x86)\TeamViewer\TeamViewer_Service.exe
    c:\users\Usertr\AppData\Roaming\Dropbox\bin\Dropbox.exe
    c:\program files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
    c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
    .
    **************************************************************************
    .
    Completion time: 2015-01-10 18:46:10 - machine was rebooted
    ComboFix-quarantined-files.txt 2015-01-10 16:46
    .
    Pre-Run: 412.439.924.736 bayt boş
    Post-Run: 411.957.293.056 bayt boş
    .
    - - End Of File - - 4229CAE88F900F67F34F9A5F8C3F31A1
    A36C5E4F47E84449FF07ED3517B43A31







  • virüs programın yok galiba sistemin virüs işgali altında
  • eset kullanıyodum ama kapatamadım combofix kullanıcam diye bende sildim taratıyorum avirayla ama çözüm yok :( cpu yu anladım klavyeden ama bi opera açtığımda %42 fiziksel bellek kullanımı oluyo bi oyunda %80-90 civarına çıkabiliyo eskiden böyle değildi ya bişey var ama bulamıyorum
  • Norton Power Eraser ile taratın.
  • Böyle bir kanıya nasıl ulaştınız acaba?

    svchost isimli zararlıkaynaklıolabileceği gibi w,ndows da bazen olan bug kaynaklı da svchost aşırı işlemci ullanımına sebep olmaktadır.

    http://answers.microsoft.com/en-us/windows/forum/windows_xp-windows_update/windows-update-svchostexe-100-cpu-in-task-manager/6b372d8b-0ca4-4042-ba37-b2a7cdcdbd06

    Bu sayfada konu ile alakalı bilgi bulabilirsiniz kolay gelsin...




  • regsvr32 qmgr.dll yi başlattan tıkladıgımdahttp://i.hizliresim.com/GpDJ5Z.png böyle bi uyarı çıkıyo devam etmelimiyim yoksa duruyim mi bi de geri kalanını pek çeviremedim ne yapıcağımı anlatabilirseniz sevinirim



    < Bu mesaj bu kişi tarafından değiştirildi pcamper -- 14 Ocak 2015; 23:24:21 >
  • 
Sayfa: 1
- x
Bildirim
mesajınız kopyalandı (ctrl+v) yapıştırmak istediğiniz yere yapıştırabilirsiniz.