Şimdi Ara

Bilgisayar Yavasladi ya da Virus bulastigindan mi suphelisiniz? [Resimli]

Daha Fazla
Bu Konudaki Kullanıcılar: Daha Az
2 Misafir - 2 Masaüstü
5 sn
31
Cevap
0
Favori
7.749
Tıklama
Daha Fazla
İstatistik
  • Konu İstatistikleri Yükleniyor
0 oy
Öne Çıkar
Sayfa: 12
Sayfaya Git
Git
sonraki
Giriş
Mesaj
  • NOT: Arkadaslar bu dokumani sizler icin hazirladim. Yalnizca kaynak belirtmek sartiyla istediginiz yerde yayinlayabilirsiniz. Ayrica Buraya lutfen tarama sonuclarini gondermeyin tarama sonuclarini 7. adimda verdigim basliga yollayin. Burada dokumanla ilgili yorumlarinizi ve diger sorularinizi / mesajalrinizi yazin. Umarim yardimci olabilmisimdir.

    Bilgisayariniz mi yavas?

    Zararli Yazilimlar:

    Performansinizi genel itibariyle en cok etkileyen sebeptir. P2P programlarinin kullanilmasiyla, internette guvenli icerik icermeyen sitelerde dolasmakla, ya da guvenlik guncellestirmelerinin eksikligi yuzunden basiniza gelebilir.

    1. Anti-Virus programinizi guncelleyin. Ve guvenli modda hard diskinizde tam bir tarama gerceklestirin. Programinizin cozebildigi sorunlari cozun. Ama sunu da unutmayin ki bazi virusler tamamen temizlenmeden once bir kac fazladan adim daha gerektirirler. Oncelikle internetten sizinle daha once ayni sorunu paylasmis kisilerin olup olmadigini arastirin. Eger sorununuza cozum bulamazsaniz o zaman yardim istemek icin DH forumlarini kullanin.

    2. Eger bu yavaslama birden olduysa ve son zamanlarda yeni bir program indirdiyseniz problem burada olabilir. Ilk once bu programi silmekle ise baslayin. Genellikle bilincli kullanicilar bir program yuklemeden once genel bir arastirma yaparlar ve zararli olup olmadigini ogrenirler. Yoksa bu sorunlarin olusmasi kacinilmazdir.

    3. Zararli yazilimlar (malware, spyware vs.) sistem performansinizi ve internet hizinizi inanilmaz olcude etkileyebilir. Anti-Spyware programinizi guncellestirin ve guvenli modda harddiskinizi tam bir tarayin. (Eger hangi Anti-Spyware programinin daha etkili oldugunu bilmiyorsaniz buradan sorabilirsiniz). Ve cozebildiginiz sorunlari cozun.

    Kontrolsuz programlar:

    4. Baslangic programlarinizi kontrol edin. Hizli baslat menusundeki programlariniz, baslangicta acilanlar, system traydakiler hepsi sisteminizi icten ice yiyen birer bocek gibidirler. O yuzden ihtiyaciniz olmayanlari devre disi birakmalisiniz. Cogu guvenlik programi baslangicta otomatik olarak acilan programlari gosterme ozelligine sahiptirler. Buradan kontrol edip isteginiz disinda acilanlari devre disi birakabilirsiniz.Hangilerinin guvenli olup olmadigi konusuna ise daha sonra deginecegim. Bu arada masaustunuzun de performansiniz uzerinde etkisi oldugunu unutmayin.

    Bakim Eksikligi:

    5. Hard diskinizi temizleyin. Kullanmadiginiz programlari kaldirin, eski dosyalarinizi CD veya DVD'ye cekin. Genellikle bitirdiginiz oyunlar, aile resimleri, arsivden cikarilmis RAR dosyalari bunlarin basinda gelir. Ayrica Windows Disk Temizleme ile gecici dosyalari temizlemeyi de unutmayin.

    6. Guvenli modda scandisk ve checkdisk araclarini kullanin ve bulunan hatalari onarin.

    7. Diskinizi birlestirin. Evet cogu kullanici bunu goz ardi eder fakat Windows dosyalari atarken genellikle bos buldugu ilk yere koyar. Bu da performansi onemli olcude dusurur. Diskinizi birlestirerek birbiri ile baglantili dosyalari yakina koyarak performansinizi artirip bu programlarin ve dosyalarin daha hizli acilmalarini saglar.

    Cogu zaman buraya kadar yapilanlar performansinizi eskiye dondurmek icin yeterlidir. Ama eger deiglse uzulmeyin:

    VIRUSLERDEN KURTULMAK ICIN GEREKLI ADIMLAR:

    1. Oncelikle asagidaki programi indirip bilgisayariniza kurun.

    Programi Indir

    2. Resimdeki gibi bir uyari alacaksiniz Tamam tiklayin.

     Bilgisayar Yavasladi ya da Virus bulastigindan mi suphelisiniz? [Resimli]


    3. Daha sonra bir uyari daha alacaksiniz ona da tamam tiklayin.

    4. Bir kac islem yaparken program size HijackThis'i bulamadigini ve ne yapmasi gerektigini soracak. HijackThis kurulu olsa bile sisteminizde Evet (Yes) tiklayin. Eger guvenlik duvariniz ve virus programiniz uyari verirse izin verin.

     Bilgisayar Yavasladi ya da Virus bulastigindan mi suphelisiniz? [Resimli]


    5. Program asagidaki gibi bir pencerede sisteminizi tarayacak biraz bekleyin.

     Bilgisayar Yavasladi ya da Virus bulastigindan mi suphelisiniz? [Resimli]


    6. Ve son olarak hersey bittikten sonra 2 ayri pencerede ve Notdefterinde size tarama sonuclarini sunulacak. Bunlari kapatmayin cunku 2sine de ihtiyacimiz olacak.

    7. Son olarak bu 2 Notdefterinde size sunulanlari bilgisayarinizdaki tum sorunlari ayrintisiyla fakat kisa ve acik bir sekilde belirterekhttp://forum.donanimhaber.com/m_9478084/tm.htm bu konuya yollayin.



    < Bu mesaj bu kişi tarafından değiştirildi serji -- 5 Temmuz 2008; 12:06:23 >







  • 2not defteri var tekinde

    1
    Deckard's System Scanner v20071014.68
    Extra logfile - please post this as an attachment with your post.
    --------------------------------------------------------------------------------

    -- System Information ----------------------------------------------------------

    Microsoft Windows XP Professional (build 2600) SP 2.0
    Architecture: X86; Language: Other (041F) - seehttp://preview.****/mhhp6

    CPU 0: Intel(R) Core(TM)2 CPU 6700 @ 2.66GHz
    CPU 1: Intel(R) Core(TM)2 CPU 6700 @ 2.66GHz
    Percentage of Memory in Use: 29%
    Physical Memory (total/avail): 2046.48 MiB / 1439.13 MiB
    Pagefile Memory (total/avail): 3939.07 MiB / 3404.19 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1921.52 MiB

    A: is Removable (No Media)
    C: is Fixed (NTFS) - 97.65 GiB total, 83.11 GiB free.
    E: is Fixed (NTFS) - 136.71 GiB total, 57.85 GiB free.
    F: is Fixed (NTFS) - 138.23 GiB total, 138.14 GiB free.
    G: is CDROM (No Media)
    H: is CDROM (No Media)

    \\.\PHYSICALDRIVE0 - ST3400633AS - 372.61 GiB - 3 partitions
    \PARTITION0 (bootable) - Yüklenebilir Dosya Sistemi - 97.65 GiB - C:
    \PARTITION1 - Extended w/Extended Int 13 - 274.95 GiB - E: - F:



    -- Security Center -------------------------------------------------------------

    AUOptions is disabled.
    Windows Internal Firewall is disabled.

    FirstRunDisabled is set.
    AntiVirusDisableNotify is set.
    FirewallDisableNotify is set.
    UpdatesDisableNotify is set.

    FW: Kaspersky Internet Security v7.0.0.125 (Kaspersky Lab)
    AV: Kaspersky Internet Security v7.0.0.125 (Kaspersky Lab)

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
    "C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
    "C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
    "C:\\Documents and Settings\\Administrator\\Desktop\\utorrent-1.8.exe"="C:\\Documents and Settings\\Administrator\\Desktop\\utorrent-1.8.exe:*:Enabled:µTorrent"
    "C:\\Documents and Settings\\Administrator\\Desktop\\programlar\\utorrent-1.8.exe"="C:\\Documents and Settings\\Administrator\\Desktop\\programlar\\utorrent-1.8.exe:*:Enabled:µTorrent"


    -- Environment Variables -------------------------------------------------------

    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\Administrator\Application Data
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=METU-95365E4B0B
    ComSpec=C:\WINDOWS\system32\cmd.exe
    FP_NO_HOST_CHECK=NO
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\Administrator
    LOGONSERVER=\\METU-95365E4B0B
    NUMBER_OF_PROCESSORS=2
    OS=Windows_NT
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\SSH Communications Security\SSH Secure Shell
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 6, GenuineIntel
    PROCESSOR_LEVEL=6
    PROCESSOR_REVISION=0f06
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    SESSIONNAME=Console
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
    TMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
    USERDOMAIN=METU-95365E4B0B
    USERNAME=Administrator
    USERPROFILE=C:\Documents and Settings\Administrator
    windir=C:\WINDOWS
    __COMPAT_LAYER=DisableNXShowUI DisableNXShowUI


    -- User Profiles ---------------------------------------------------------------

    fatih [I](admin)[/I]
    Administrator [I](admin)[/I]


    -- Add/Remove Programs ---------------------------------------------------------

    --> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
    --> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
    --> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
    --> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
    --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL
    --> C:\WINDOWS\UNRecode.exe /UNINSTALL
    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 8 - Turkish --> MsiExec.exe /I{AC76BA86-7AD7-1055-7B44-A80000000000}
    Advanced WindowsCare 2.50 Personal --> "C:\Program Files\IObit\Advanced WindowsCare V2\unins000.exe"
    ASUS Gamer OSD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}\setup.exe" -l0x9 -removeonly
    Call of Duty(R) 4 - Modern Warfare(TM) --> C:\Program Files\InstallShield Installation Information\{E48469CC-635E-4FD5-A122-1497C286D217}\setup.exe -runfromtemp -l0x0409
    Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch --> C:\Program Files\InstallShield Installation Information\{8A15B7D9-908A-4EF9-BA84-5AEDE61743EE}\setup.exe -runfromtemp -l0x0409
    Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch --> C:\Program Files\InstallShield Installation Information\{931C37FC-594D-43A9-B10F-A2F2B1F03498}\setup.exe -runfromtemp -l0x0409
    CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
    Celestia 1.5.1 --> "C:\Program Files\Celestia\unins000.exe"
    EVEREST Home Edition v2.20 --> "C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
    Free Download Manager 2.5 --> "C:\Program Files\Free Download Manager\unins000.exe"
    GameSpy Arcade --> C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
    GOM Player --> "C:\Program Files\GRETECH\GomPlayer\Uninstall.exe"
    Google Earth --> MsiExec.exe /I{97C0EA4A-1A0B-4C53-ACEB-49984DA79C90}
    GSview 4.6 --> C:\Program Files\Gv\gsview\uninstgs.exe "C:\Program Files\Gv\gsview\uninstal.txt"
    High Definition Audio Driver Package - KB888111 --> C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe
    Kaspersky Internet Security 7.0 --> MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}
    Kaspersky Internet Security 7.0 --> MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}
    Messenger Plus! Live --> "C:\Program Files\Messenger Plus! Live\Uninstall.exe"
    Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{9011041F-6000-11D3-8CFE-0150048383C9}
    Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348) --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
    Microsoft Visual Studio 6.0 Enterprise Edition --> "C:\Program Files\Microsoft Visual Studio\Common\Setup\1033\Setup.exe"
    Microsoft VM for Java --> RunDll32 advpack.dll,LaunchINFSection java.inf,UnInstall
    Microsoft Web Publishing Wizard 1.53 --> RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie3x86.inf,WebPostUninstall
    Mozilla Firefox (3.0) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    Nero 7 Premium --> MsiExec.exe /I{70AB1576-7883-2313-C650-7A71270B1055}
    NVIDIA Drivers --> C:\WINDOWS\system32\nvuninst.exe UninstallGUI
    NVIDIA ForceWare Network Access Manager --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1055
    Opera 9.50 --> MsiExec.exe /X{7472B5B4-3FB7-446F-BC78-6BBA506EC473}
    SoundMAX --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe" -l0x1f -removeonly
    SWAT 4 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe /M{8E1CCF20-9E12-4824-BD59-7AD9E0486DD8} uninstall
    TuneUp Utilities 2008 --> MsiExec.exe /I{5888428E-699C-4E71-BF71-94EE06B497DA}
    USB2.0 PC Camera (SN9C201&202) --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{75438C0E-9925-412E-AD85-D0E71C6CE2ED}\Setup.exe" -l0x9
    USRobotics Wireless USB Adapter --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{9061D8EC-67C5-4FD1-90D6-F6F5BE012707}
    Windows Live Messenger --> MsiExec.exe /I{CB7D9F91-E82E-450C-B884-3DB9A7099C73}
    Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
    WinRAR arşiv yöneticisi --> C:\Program Files\WinRAR\uninstall.exe
    Xfire (remove only) --> "C:\Program Files\Xfire\uninst.exe"
    Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL


    -- Application Event Log -------------------------------------------------------

    Event Record #/Type1003 / Error
    Event Submitted/Written: 07/05/2008 02:12:52 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Hata uygulaması drwtsn32.exe, sürüm 5.1.2600.0, hata modülü dbghelp.dll, sürümü 5.1.2600.2180, hata adresi 0x0001295d.
    Ortama özel olay [drwtsn32.exe!ws!] için işleniyor

    Event Record #/Type1001 / Error
    Event Submitted/Written: 07/05/2008 02:11:20 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Hata uygulaması explorer.exe, sürüm 6.0.2900.2180, hata modülü unknown, sürümü 0.0.0.0, hata adresi 0x029816d3.
    Ortama özel olay [explorer.exe!ws!] için işleniyor

    Event Record #/Type985 / Error
    Event Submitted/Written: 07/05/2008 01:15:44 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Hata uygulaması explorer.exe, sürüm 6.0.2900.2180, hata modülü unknown, sürümü 0.0.0.0, hata adresi 0x020216d3.
    Ortama özel olay [explorer.exe!ws!] için işleniyor

    Event Record #/Type983 / Error
    Event Submitted/Written: 07/05/2008 01:15:33 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Hata uygulaması explorer.exe, sürüm 6.0.2900.2180, hata modülü unknown, sürümü 0.0.0.0, hata adresi 0x025316d3.
    Ortama özel olay [explorer.exe!ws!] için işleniyor

    Event Record #/Type981 / Error
    Event Submitted/Written: 07/05/2008 01:10:49 PM
    Event ID/Source: 1000 / Application Error
    Event Description:
    Hata uygulaması drwtsn32.exe, sürüm 5.1.2600.0, hata modülü dbghelp.dll, sürümü 5.1.2600.2180, hata adresi 0x0001295d.
    Ortama özel olay [drwtsn32.exe!ws!] için işleniyor



    -- Security Event Log ----------------------------------------------------------

    No Errors/Warnings found.


    -- System Event Log ------------------------------------------------------------

    Event Record #/Type4132 / Warning
    Event Submitted/Written: 07/05/2008 02:06:54 PM
    Event ID/Source: 1003 / Dhcp
    Event Description:
    Bilgisayarınız, ağ adresi 0014C13F6C8B olan Ağ Kartı için adresini ağdan (DHCP
    Sunucusu'ndan) yenileyemedi. Aşağıdaki hata oluştu:
    %%1223.
    Bilgisayarınız, ağ adresi (DHCP) sunucusundan kendisi bir adres almak için
    denemeye devam edecek.

    Event Record #/Type4131 / Warning
    Event Submitted/Written: 07/05/2008 02:06:47 PM
    Event ID/Source: 1003 / Dhcp
    Event Description:
    Bilgisayarınız, ağ adresi 0014C13F6C8B olan Ağ Kartı için adresini ağdan (DHCP
    Sunucusu'ndan) yenileyemedi. Aşağıdaki hata oluştu:
    %%1223.
    Bilgisayarınız, ağ adresi (DHCP) sunucusundan kendisi bir adres almak için
    denemeye devam edecek.

    Event Record #/Type4129 / Warning
    Event Submitted/Written: 07/05/2008 02:06:41 PM
    Event ID/Source: 1003 / Dhcp
    Event Description:
    Bilgisayarınız, ağ adresi 0014C13F6C8B olan Ağ Kartı için adresini ağdan (DHCP
    Sunucusu'ndan) yenileyemedi. Aşağıdaki hata oluştu:
    %%1223.
    Bilgisayarınız, ağ adresi (DHCP) sunucusundan kendisi bir adres almak için
    denemeye devam edecek.

    Event Record #/Type4127 / Warning
    Event Submitted/Written: 07/05/2008 02:06:35 PM
    Event ID/Source: 1003 / Dhcp
    Event Description:
    Bilgisayarınız, ağ adresi 0014C13F6C8B olan Ağ Kartı için adresini ağdan (DHCP
    Sunucusu'ndan) yenileyemedi. Aşağıdaki hata oluştu:
    %%1223.
    Bilgisayarınız, ağ adresi (DHCP) sunucusundan kendisi bir adres almak için
    denemeye devam edecek.

    Event Record #/Type4125 / Warning
    Event Submitted/Written: 07/05/2008 02:06:27 PM
    Event ID/Source: 1003 / Dhcp
    Event Description:
    Bilgisayarınız, ağ adresi 0014C13F6C8B olan Ağ Kartı için adresini ağdan (DHCP
    Sunucusu'ndan) yenileyemedi. Aşağıdaki hata oluştu:
    %%1223.
    Bilgisayarınız, ağ adresi (DHCP) sunucusundan kendisi bir adres almak için
    denemeye devam edecek.



    -- End of Deckard's System Scanner: finished at 2008-07-05 14:13:01 ------------

    2.
    Deckard's System Scanner v20071014.68
    Run by Administrator on 2008-07-05 14:10:14
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 5 Restore Point(s) --
    8: 2008-07-05 11:10:16 UTC - RP8 - Deckard's System Scanner Restore Point
    7: 2008-07-04 23:20:13 UTC - RP7 - Removed Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch
    6: 2008-07-04 08:33:06 UTC - RP6 - Installed Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch
    5: 2008-07-03 14:32:53 UTC - RP5 - Sistem Denetleme Noktası
    4: 2008-06-30 19:21:35 UTC - RP4 - Google Earth yüklendi.


    -- First Restore Point --
    1: 2008-06-26 11:37:16 UTC - RP1 - Sistem Denetleme Noktası


    Backed up registry hives.
    Performed disk cleanup.



    -- HijackThis (run as Administrator.exe) ---------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:11:15, on 05.07.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\ATKKBService.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\FixCamera.exe
    C:\WINDOWS\tsnp2std.exe
    C:\WINDOWS\vsnp2std.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Free Download Manager\fdm.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\USRobotics\Wireless USB Manager\USR54G.exe
    C:\Program Files\Xfire\xfire.exe
    C:\Documents and Settings\Administrator\Desktop\dss.exe
    C:\PROGRA~1\TRENDM~1\HIJACK~1\Administrator.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Bağı Yardımı - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
    O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
    O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
    O4 - Global Startup: USRobotics Wireless USB Adapter.lnk = C:\Program Files\USRobotics\Wireless USB Manager\USR54G.exe
    O8 - Extra context menu item: Free Download Manager ile indir - file://C:\Program Files\Free Download Manager\dllink.htm
    O8 - Extra context menu item: Free Download Manager ile seçileni indir - file://C:\Program Files\Free Download Manager\dlselected.htm
    O8 - Extra context menu item: Free Download Manager ile tümünü indir - file://C:\Program Files\Free Download Manager\dlall.htm
    O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Reklam Engelleyici'ye ekle - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
    O8 - Extra context menu item: Videoyu Free Download Manager ile indir - file://C:\Program Files\Free Download Manager\dlfvideo.htm
    O9 - Extra button: Web Koruması İstatistikleri - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
    O9 - Extra button: Araştır - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {D0BB3ACE-4ED3-4D65-BB86-1A0C6CAF351F} (AvaLaunch Control) -http://212.175.239.246:81/avaLaunch94.cab
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cc.metu.edu.tr,metu.edu.tr
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cc.metu.edu.tr,metu.edu.tr
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cc.metu.edu.tr,metu.edu.tr
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
    O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe

    --
    End of file - 6552 bytes

    -- File Associations -----------------------------------------------------------

    All associations okay.


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R1 asuskbnt (Enhanced Display Driver Helper Service) - c:\windows\system32\drivers\atkkbnt.sys <Not Verified; ASUSTeK COMPUTER INC.; ASUS Help driver For Keyboard Service.>
    R2 EIO - c:\windows\system32\drivers\eio.sys <Not Verified; ASUSTeK Computer Inc.; ASUS Kernel Mode Driver for NT>
    R3 SNP2STD (USB2.0 PC Camera (SNP2STD)) - c:\windows\system32\drivers\snp2sxp.sys <Not Verified; ; USB2.0 PC Camera driver>
    R3 Video3D (ASUS Video3D Service) - c:\windows\system32\drivers\video3d32.sys <Not Verified; ASUSTeK COMPUTER INC.; ASUS Video3D driver>
    R3 ZDPSp50 (ZDPSp50 NDIS Protocol Driver) - c:\windows\system32\drivers\zdpsp50.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    R2 ATKKeyboardService (ATK Keyboard Service) - c:\windows\atkkbservice.exe <Not Verified; ASUSTeK COMPUTER INC.; ASUS Keyboard Service>
    R2 ForceWare Intelligent Application Manager (IAM) - c:\program files\nvidia corporation\networkaccessmanager\bin\nsvcappflt.exe <Not Verified; ; app_filter Module>


    -- Device Manager: Disabled ----------------------------------------------------

    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: Çoklu Ortam Video Denetleyicisi
    Device ID: PCI\VEN_109E&DEV_036E&SUBSYS_18521852&REV_02\4&1A82106&0&3078
    Manufacturer:
    Name: Çoklu Ortam Video Denetleyicisi
    PNP Device ID: PCI\VEN_109E&DEV_036E&SUBSYS_18521852&REV_02\4&1A82106&0&3078
    Service:

    Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
    Description: Çoklu Ortam Denetleyicisi
    Device ID: PCI\VEN_109E&DEV_0878&SUBSYS_18521852&REV_02\4&1A82106&0&3178
    Manufacturer:
    Name: Çoklu Ortam Denetleyicisi
    PNP Device ID: PCI\VEN_109E&DEV_0878&SUBSYS_18521852&REV_02\4&1A82106&0&3178
    Service:


    -- Scheduled Tasks -------------------------------------------------------------

    2008-07-05 14:06:52 502 --a------ C:\WINDOWS\Tasks\1-Click Maintenance.job


    -- Files created between 2008-06-05 and 2008-07-05 -----------------------------

    2008-07-05 14:10:48 0 d-------- C:\Program Files\Trend Micro
    2008-07-05 02:13:10 0 dr-h----- C:\Documents and Settings\Administrator\Recent
    2008-07-04 14:33:24 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2008-07-04 13:56:56 0 d-------- C:\Program Files\CCleaner
    2008-07-01 21:19:43 0 d-------- C:\Program Files\Celestia
    2008-07-01 17:57:16 0 d-------- C:\Documents and Settings\fatih\Application Data\GRETECH
    2008-07-01 15:41:25 0 d-------- C:\Documents and Settings\fatih\Application Data\Google
    2008-06-30 22:22:06 0 d-------- C:\Documents and Settings\Administrator\Application Data\Google
    2008-06-30 22:21:37 0 d-------- C:\Program Files\Google
    2008-06-29 17:45:54 0 d-------- C:\Program Files\Lavalys
    2008-06-29 17:06:31 0 d-------- C:\WINDOWS\system32\dns
    2008-06-28 15:07:47 0 d-------- C:\Documents and Settings\fatih\Application Data\Xfire
    2008-06-26 22:25:52 0 d-------- C:\Documents and Settings\fatih\Application Data\TuneUp Software
    2008-06-26 22:22:41 0 d---s---- C:\Documents and Settings\fatih\UserData
    2008-06-26 15:03:03 43520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
    2008-06-26 15:02:33 0 d-------- C:\Program Files\GameSpy Arcade
    2008-06-26 14:56:17 0 d-------- C:\Program Files\Sierra
    2008-06-26 14:47:58 0 d-------- C:\Documents and Settings\fatih\Application Data\Ahead
    2008-06-26 13:25:36 0 d-------- C:\Documents and Settings\Administrator\Application Data\TuneUp Software
    2008-06-26 13:25:28 0 d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
    2008-06-26 13:25:23 0 d-------- C:\Program Files\TuneUp Utilities 2008
    2008-06-26 13:25:01 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2008-06-26 02:23:32 0 d-------- C:\Program Files\Web Publish
    2008-06-26 02:18:05 140048 --a------ C:\WINDOWS\system32\jit.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
    2008-06-26 02:18:05 135168 --a------ C:\WINDOWS\system32\javaee.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
    2008-06-26 02:18:05 313856 --a------ C:\WINDOWS\system32\dx3j.dll <Not Verified; Microsoft Corporation; Microsoft® DirectX for Java>
    2008-06-26 02:18:05 42496 --a------ C:\WINDOWS\setdebug.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
    2008-06-26 02:18:05 6550 --a------ C:\WINDOWS\jautoexp.dat
    2008-06-26 02:18:02 147456 --a------ C:\WINDOWS\wjview.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® İşletim Sistemi>
    2008-06-26 02:18:02 113 --a------ C:\WINDOWS\system32\zonedon.reg
    2008-06-26 02:18:02 113 --a------ C:\WINDOWS\system32\zonedoff.reg
    2008-06-26 02:18:02 207872 --a------ C:\WINDOWS\system32\vmhelper.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® İşletim Sistemi>
    2008-06-26 02:18:02 73728 --a------ C:\WINDOWS\system32\msjdbc10.dll <Not Verified; Microsoft Corporation; Microsoft JDBC Bridge>
    2008-06-26 02:18:02 843024 --a------ C:\WINDOWS\system32\msjava.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
    2008-06-26 02:18:02 155920 --a------ C:\WINDOWS\system32\msawt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
    2008-06-26 02:18:02 14848 --a------ C:\WINDOWS\system32\jdbgmgr.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
    2008-06-26 02:18:02 361744 --a------ C:\WINDOWS\system32\javart.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
    2008-06-26 02:18:02 32528 --a------ C:\WINDOWS\system32\javaprxy.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
    2008-06-26 02:18:02 209168 --a------ C:\WINDOWS\system32\javacypt.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® İşletim Sistemi>
    2008-06-26 02:18:02 154112 --a------ C:\WINDOWS\jview.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® İşletim Sistemi>
    2008-06-26 02:18:01 103424 --a------ C:\WINDOWS\extrac32.exe <Not Verified; Microsoft Corporation; Microsoft (R) CAB File Extract Utility>
    2008-06-26 02:18:01 44544 --a------ C:\WINDOWS\clspack.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
    2008-06-26 01:00:36 94208 --a------ C:\WINDOWS\amcap.exe <Not Verified; Microsoft Corporation; DirectX 8.1 Sample>
    2008-06-26 01:00:35 20480 --a------ C:\WINDOWS\FixCamera.exe <Not Verified; ; CameraFixer Application>
    2008-06-26 01:00:33 675840 --a------ C:\WINDOWS\vsnp2std.exe <Not Verified; Sonix; CameraMonitor Application>
    2008-06-26 01:00:33 262144 --a------ C:\WINDOWS\tsnp2std.exe <Not Verified; ; tsnp2std>
    2008-06-26 01:00:33 10305280 --a------ C:\WINDOWS\system32\drivers\snp2sxp.sys <Not Verified; ; USB2.0 PC Camera driver>
    2008-06-26 01:00:33 24832 --a------ C:\WINDOWS\system32\drivers\sncamd.sys <Not Verified; ; USB2.0 PC Camera driver>
    2008-06-26 01:00:31 147456 --a------ C:\WINDOWS\rsnp2std.dll <Not Verified; ; ResourceDLL>
    2008-06-26 01:00:30 61440 --a------ C:\WINDOWS\vsnp2std.dll <Not Verified; Sonix; >
    2008-06-26 01:00:30 53248 --a------ C:\WINDOWS\system32\csnp2std.dll <Not Verified; ; InstallUtil>
    2008-06-26 01:00:30 0 d-------- C:\Program Files\Common Files\snp2std
    2008-06-25 18:25:15 0 d-------- C:\Documents and Settings\fatih\Contacts
    2008-06-25 11:12:45 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
    2008-06-25 02:37:52 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
    2008-06-25 02:37:45 0 d-------- C:\Program Files\Common Files\Adobe
    2008-06-25 02:33:21 0 d-------- C:\Program Files\IObit
    2008-06-25 01:49:14 0 d-------- C:\WINDOWS\SHELLNEW
    2008-06-25 00:03:13 0 d-------- C:\Documents and Settings\fatih\Application Data\Macromedia
    2008-06-25 00:03:13 0 d-------- C:\Documents and Settings\fatih\Application Data\Adobe
    2008-06-24 23:54:16 0 d-------- C:\Documents and Settings\fatih\Application Data\Mozilla
    2008-06-24 20:41:48 0 d-------- C:\Documents and Settings\fatih\Application Data\Identities
    2008-06-24 20:41:35 0 d--h----- C:\Documents and Settings\fatih\Templates <TEMPLA~1>
    2008-06-24 20:41:35 0 dr------- C:\Documents and Settings\fatih\Start Menu <STARTM~1>
    2008-06-24 20:41:35 0 dr------- C:\Documents and Settings\fatih\Sık Kullanılanlar <SKKULL~1>
    2008-06-24 20:41:35 0 dr-h----- C:\Documents and Settings\fatih\SendTo
    2008-06-24 20:41:35 0 dr-h----- C:\Documents and Settings\fatih\Recent
    2008-06-24 20:41:35 0 d--h----- C:\Documents and Settings\fatih\PrintHood <PRINTH~1>
    2008-06-24 20:41:35 2097152 --ah----- C:\Documents and Settings\fatih\NTUSER.DAT
    2008-06-24 20:41:35 0 d--h----- C:\Documents and Settings\fatih\NetHood
    2008-06-24 20:41:35 0 d--h----- C:\Documents and Settings\fatih\Local Settings <LOCALS~1>
    2008-06-24 20:41:35 0 d-------- C:\Documents and Settings\fatih\Desktop
    2008-06-24 20:41:35 0 d---s---- C:\Documents and Settings\fatih\Cookies
    2008-06-24 20:41:35 0 dr------- C:\Documents and Settings\fatih\Belgelerim <BELGEL~1>
    2008-06-24 20:41:35 0 dr-h----- C:\Documents and Settings\fatih\Application Data <APPLIC~1>
    2008-06-24 20:41:35 0 d---s---- C:\Documents and Settings\fatih\Application Data\Microsoft
    2008-06-24 20:40:23 0 d-------- C:\Documents and Settings\LocalService\Application Data\Xfire
    2008-06-24 20:40:19 0 d-------- C:\WINDOWS\NV29403748.TMP
    2008-06-24 20:39:57 0 d-------- C:\NVIDIA
    2008-06-24 20:32:28 0 d-------- C:\Program Files\Activision
    2008-06-24 19:17:51 0 d-------- C:\Documents and Settings\Administrator\Application Data\Free Download Manager
    2008-06-24 19:17:49 0 d-------- C:\Program Files\Free Download Manager
    2008-06-24 19:17:49 0 d-------- C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
    2008-06-24 18:58:31 96966 --a------ C:\WINDOWS\system32\drivers\klin.dat
    2008-06-24 18:58:31 88774 --a------ C:\WINDOWS\system32\drivers\klick.dat
    2008-06-24 18:58:11 0 d-------- C:\Program Files\Kaspersky Lab
    2008-06-24 18:58:11 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
    2008-06-24 18:58:10 277280 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
    2008-06-24 18:58:10 7967264 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
    2008-06-24 18:57:48 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
    2008-06-24 18:29:29 0 d-------- C:\Documents and Settings\Administrator\Application Data\Opera
    2008-06-24 18:29:26 0 d-------- C:\Program Files\Opera
    2008-06-24 18:01:31 0 d-------- C:\Documents and Settings\Administrator\Application Data\Ahead
    2008-06-24 18:01:01 0 d-------- C:\Program Files\Nero
    2008-06-24 18:01:01 0 d-------- C:\Program Files\Common Files\Ahead
    2008-06-24 16:10:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
    2008-06-24 13:48:32 0 d--hs---- C:\WINDOWS\Installer
    2008-06-24 13:48:31 0 d-------- C:\Program Files\Common Files\ODBC
    2008-06-24 13:48:28 0 dr------- C:\Program Files
    2008-06-24 13:48:28 0 d-------- C:\Program Files\Common Files
    2008-06-24 13:48:28 0 d-------- C:\Program Files\Common Files\SpeechEngines
    2008-06-24 13:48:04 0 d--h----- C:\Documents and Settings\Default User\Templates <TEMPLA~1>
    2008-06-24 13:48:04 0 dr------- C:\Documents and Settings\Default User\Start Menu <STARTM~1>
    2008-06-24 13:48:04 0 d-------- C:\Documents and Settings\Default User\Sık Kullanılanlar <SKKULL~1>
    2008-06-24 13:48:04 0 dr-h----- C:\Documents and Settings\Default User\SendTo
    2008-06-24 13:48:04 0 d--h----- C:\Documents and Settings\Default User\Recent
    2008-06-24 13:48:04 0 d--h----- C:\Documents and Settings\Default User\PrintHood <PRINTH~1>
    2008-06-24 13:48:04 0 d--h----- C:\Documents and Settings\Default User\NetHood
    2008-06-24 13:48:04 0 dr-h----- C:\Documents and Settings\Default User\Local Settings <LOCALS~1>
    2008-06-24 13:48:04 0 d-------- C:\Documents and Settings\Default User\Desktop
    2008-06-24 13:48:04 0 d---s---- C:\Documents and Settings\Default User\Cookies
    2008-06-24 13:48:04 0 d-------- C:\Documents and Settings\Default User\Belgelerim <BELGEL~1>
    2008-06-24 13:48:04 0 d--h----- C:\Documents and Settings\All Users\Templates <TEMPLA~1>
    2008-06-24 13:48:04 0 dr------- C:\Documents and Settings\All Users\Start Menu <STARTM~1>
    2008-06-24 13:48:04 0 d-------- C:\Documents and Settings\All Users\Sık Kullanılanlar <SKKULL~1>
    2008-06-24 13:48:04 0 d-------- C:\Documents and Settings\All Users\Desktop
    2008-06-24 13:48:04 0 dr------- C:\Documents and Settings\All Users\Belgeler
    2008-06-24 13:46:15 0 d-------- C:\WINDOWS\system32\CatRoot2
    2008-06-24 13:46:15 0 d-------- C:\WINDOWS\system32\CatRoot
    2008-06-24 13:46:10 0 dr-h----- C:\Documents and Settings\Default User\Application Data <APPLIC~1>
    2008-06-24 13:46:10 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
    2008-06-24 13:46:10 0 dr-h----- C:\Documents and Settings\All Users\Application Data <APPLIC~1>
    2008-06-24 13:46:10 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2008-06-24 13:45:54 0 d--hs---- C:\System Volume Information
    2008-06-24 13:45:54 0 d-------- C:\Documents and Settings
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\WinSxS
    2008-06-24 13:40:50 0 dr------- C:\WINDOWS\Web
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\twain_32
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\wins
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\wbem
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\usmt
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\spool
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\ShellExt
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\Setup
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\ras
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\oobe
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\npp
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\mui
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\inetsrv
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\IME
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\icsxml
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\ias
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\export
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\drivers
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\drivers\etc
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\drivers\disdn
    2008-06-24 13:40:50 0 dr-hs--c- C:\WINDOWS\system32\dllcache
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\dhcp
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\config
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\3com_dmi
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\3076
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\2052
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\1055
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\1054
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\1042
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\1041
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\1037
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\1033
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\1031
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\1028
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system32\1025
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\system
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\security
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\Resources
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\repair
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\Provisioning
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\PeerNet
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\pchealth
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\mui
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\msapps
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\msagent
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\Media
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\java
    2008-06-24 13:40:50 0 d--h----- C:\WINDOWS\inf
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\ime
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\Help
    2008-06-24 13:40:50 0 dr--s---- C:\WINDOWS\Fonts
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\ehome
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\Driver Cache
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\Debug
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\Cursors
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\Connection Wizard
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\Config
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\AppPatch
    2008-06-24 13:40:50 0 d-------- C:\WINDOWS\addins
    2008-06-24 13:05:02 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
    2008-06-24 13:02:30 0 d-------- C:\Program Files\Windows Live
    2008-06-24 13:02:29 0 d-------- C:\Program Files\Messenger Plus! Live
    2008-06-24 12:57:38 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
    2008-06-24 12:57:37 0 d--hs---- C:\WINDOWS\ftpcache
    2008-06-24 12:45:52 0 d-------- C:\Documents and Settings\All Users\Application Data\GRETECH
    2008-06-24 12:45:36 0 d-------- C:\Documents and Settings\Administrator\Application Data\GRETECH
    2008-06-24 12:45:13 0 d-------- C:\Program Files\GRETECH
    2008-06-24 12:37:55 0 --a------ C:\WINDOWS\nsreg.dat
    2008-06-24 12:37:53 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
    2008-06-24 12:32:43 0 d-------- C:\WINDOWS\system32\LogFiles
    2008-06-24 12:32:31 0 d-------- C:\WINDOWS\system32\drivers\umdf
    2008-06-24 12:31:37 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
    2008-06-24 12:29:05 0 d-------- C:\Documents and Settings\NetworkService\Application Data\Xfire
    2008-06-24 11:38:04 0 d-------- C:\Documents and Settings\Administrator\Contacts
    2008-06-24 11:37:45 0 d------c- C:\WINDOWS\system32\DRVSTORE
    2008-06-24 11:37:18 0 d-------- C:\Program Files\MSN Messenger
    2008-06-24 11:34:32 0 d-------- C:\Documents and Settings\Administrator\Application Data\Xfire
    2008-06-24 11:34:31 0 d-------- C:\Program Files\Xfire
    2008-06-24 11:30:57 0 d---s---- C:\Documents and Settings\Administrator\UserData
    2008-06-24 11:27:51 0 d-------- C:\Program Files\USRobotics
    2008-06-24 11:27:41 0 d-------- C:\WINDOWS\Downloaded Installations
    2008-06-24 11:27:08 0 d-------- C:\Temp
    2008-06-24 11:24:58 0 d-------- C:\WINDOWS\system32\appmgmt
    2008-06-24 11:21:51 0 d-------- C:\Program Files\My Company Name
    2008-06-24 11:21:34 10752 --a------ C:\WINDOWS\system32\drivers\Video3D32.sys <Not Verified; ASUSTeK COMPUTER INC.; ASUS Video3D driver>
    2008-06-24 11:21:34 196608 --a------ C:\WINDOWS\system32\drivers\nVivid.bin
    2008-06-24 11:21:34 196608 --a------ C:\WINDOWS\system32\drivers\nStandard.bin
    2008-06-24 11:21:34 196608 --a------ C:\WINDOWS\system32\drivers\nAsmedia.bin
    2008-06-24 11:21:34 196608 --a------ C:\WINDOWS\system32\drivers\nAdvanced.bin
    2008-06-24 11:21:34 8704 --a------ C:\WINDOWS\system32\drivers\Bravo.sys <Not Verified; ASMT; Microsoft(R) Windows NT(R) Operating System>
    2008-06-24 11:21:34 196608 --a------ C:\WINDOWS\system32\drivers\aVivid.bin
    2008-06-24 11:21:34 11008 --a------ C:\WINDOWS\system32\drivers\atkkbnt.sys <Not Verified; ASUSTeK COMPUTER INC.; ASUS Help driver For Keyboard Service.>
    2008-06-24 11:21:34 196608 --a------ C:\WINDOWS\system32\drivers\aStandard.bin
    2008-06-24 11:21:34 196608 --a------ C:\WINDOWS\system32\drivers\aAsmedia.bin
    2008-06-24 11:21:34 196608 --a------ C:\WINDOWS\system32\drivers\aAdvanced.bin
    2008-06-24 11:21:34 944128 --a------ C:\WINDOWS\system32\ATKOSDX32.dll <Not Verified; ASUSTeK COMPUTER INC.; ASUS On-Screen Display For 3D Game>
    2008-06-24 11:21:34 11136 --a------ C:\WINDOWS\system32\ATKOSDMini.DLL
    2008-06-24 11:21:34 39424 --a------ C:\WINDOWS\system32\ATKOGL32.dll <Not Verified; ASUSTeK COMPUTER INC.; ASUSTeK Computer Inc. AsusOGL>
    2008-06-24 11:21:34 1695744 --a------ C:\WINDOWS\system32\ATKDispCPL.dll <Not Verified; ASUSTeK COMPUTER INC.; ASUS Display Property Page>
    2008-06-24 11:21:34 249216 --a------ C:\WINDOWS\system32\ATKDISP.dll <Not Verified; ASUSTeK Computer Inc.; ASUS Windows 2000/XP Display Driver>
    2008-06-24 11:21:34 46080 --a------ C:\WINDOWS\system32\aseng.dll
    2008-06-24 11:21:34 110592 --a------ C:\WINDOWS\R5ClkLib.dll <Not Verified; ; Overclocker>
    2008-06-24 11:21:34 114688 --a------ C:\WINDOWS\OneTouchVga.dll <Not Verified; ASUSTek; ASUS OneTouchVga>
    2008-06-24 11:21:34 20480 --a------ C:\WINDOWS\HyperDrive.exe <Not Verified; ; HyperDrive Application>
    2008-06-24 11:21:34 15360 --a------ C:\WINDOWS\EIO64.sys <Not Verified; ASUSTeK Computer Inc.; ASUS Kernel Mode Driver for NT>
    2008-06-24 11:21:34 12288 --a------ C:\WINDOWS\EIO.sys <Not Verified; ASUSTeK Computer Inc.; ASUS Kernel Mode Driver for NT>
    2008-06-24 11:21:34 90112 --a------ C:\WINDOWS\EIO.dll <Not Verified; ASUSTek Computer Inc.,; ASUS EIO.DLL>
    2008-06-24 11:21:34 258560 --a------ C:\WINDOWS\ATKKBService.exe <Not Verified; ASUSTeK COMPUTER INC.; ASUS Keyboard Service>
    2008-06-24 11:21:34 163840 --a------ C:\WINDOWS\atistclk.dll <Not Verified; ATI Technologies Inc.; ATI WinClk DLL>
    2008-06-24 11:21:34 188416 --a------ C:\WINDOWS\atipdlxx.dll <Not Verified; ATI Technologies, Inc.; ATI Desktop Component>
    2008-06-24 11:21:34 7680 --a------ C:\WINDOWS\atillk64.sys <Not Verified; Overclocking Tool; Overclocking Tool>
    2008-06-24 11:21:34 15872 --a------ C:\WINDOWS\atikia64.sys <Not Verified; Overclocking Tool; Overclocking Tool>
    2008-06-24 11:21:34 5376 --a------ C:\WINDOWS\atidgllk.sys <Not Verified; Overclocking Tool; Overclocking Tool>
    2008-06-24 11:21:34 639046 --a------ C:\WINDOWS\aticlocklib.dll
    2008-06-24 11:21:34 73728 --a------ C:\WINDOWS\ASUSRC.dll <Not Verified; ASUS; ASUSRC>
    2008-06-24 11:20:37 0 d-------- C:\WINDOWS\nview
    2008-06-24 11:19:19 12288 -ra------ C:\WINDOWS\system32\drivers\EIO.sys <Not Verified; ASUSTeK Computer Inc.; ASUS Kernel Mode Driver for NT>
    2008-06-24 11:14:15 53248 -----n--- C:\WINDOWS\system32\wdmioctl.dll <Not Verified; Analog Devices Inc.; Analog Devices Inc. wdmioctl>
    2008-06-24 11:14:15 1285632 -----n--- C:\WINDOWS\system32\SMMedia.dll <Not Verified; Analog Devices; SoundMAX Integrated Digital Audio>
    2008-06-24 11:14:14 49152 -----n--- C:\WINDOWS\system32\DSndUp.exe <Not Verified; Analog Devices Inc.; adi DSndUp>
    2008-06-24 11:14:14 45056 -----n--- C:\WINDOWS\system32\CleanUp.exe <Not Verified; adi; adi CleanUp>
    2008-06-24 11:14:14 0 d-------- C:\Program Files\Analog Devices
    2008-06-24 11:11:30 0 d--hs---- C:\WINDOWS\CSC
    2008-06-24 11:10:12 0 d-------- C:\WINDOWS\ASUSInstAll
    2008-06-24 11:08:28 0 d-------- C:\Program Files\NVIDIA Corporation
    2008-06-24 11:07:35 0 d-------- C:\WINDOWS\system32\ReinstallBackups
    2008-06-24 11:07:25 0 d-------- C:\WINDOWS\NV27922796.TMP
    2008-06-24 11:07:04 486400 -ra------ C:\WINDOWS\system32\AsusSetup.exe <Not Verified; ASUS; AsusSetup>
    2008-06-24 11:05:18 10288 --a------ C:\WINDOWS\system32\drivers\ASUSHWIO.SYS
    2008-06-24 11:04:18 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
    2008-06-24 11:04:16 0 d-------- C:\Program Files\SSH Communications Security
    2008-06-24 11:04:16 0 d--h----- C:\Program Files\InstallShield Installation Information
    2008-06-24 11:04:13 0 d-------- C:\Program Files\Common Files\InstallShield
    2008-06-24 11:04:12 0 d-------- C:\Program Files\Gv
    2008-06-24 11:03:46 0 d-------- C:\Program Files\Network Associates
    2008-06-24 11:03:39 0 d-------- C:\Program Files\GDI Detection Tool
    2008-06-24 11:03:37 0 d--h----- C:\Documents and Settings\Administrator\Templates <TEMPLA~1>
    2008-06-24 11:03:37 0 dr------- C:\Documents and Settings\Administrator\Start Menu <STARTM~1>
    2008-06-24 11:03:37 0 dr------- C:\Documents and Settings\Administrator\Sık Kullanılanlar <SKKULL~1>
    2008-06-24 11:03:37 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
    2008-06-24 11:03:37 0 d--h----- C:\Documents and Settings\Administrator\PrintHood <PRINTH~1>
    2008-06-24 11:03:37 3932160 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
    2008-06-24 11:03:37 0 d--h----- C:\Documents and Settings\Administrator\NetHood
    2008-06-24 11:03:37 0 d--h----- C:\Documents and Settings\Administrator\Local Settings <LOCALS~1>
    2008-06-24 11:03:37 0 d-------- C:\Documents and Settings\Administrator\Desktop
    2008-06-24 11:03:37 0 d---s---- C:\Documents and Settings\Administrator\Cookies
    2008-06-24 11:03:37 0 dr------- C:\Documents and Settings\Administrator\Belgelerim <BELGEL~1>
    2008-06-24 11:03:37 0 dr-h----- C:\Documents and Settings\Administrator\Application Data <APPLIC~1>
    2008-06-24 11:03:31 0 d-------- C:\WINDOWS\SoftwareDistribution
    2008-06-24 11:03:29 0 d---s---- C:\WINDOWS\system32\Microsoft
    2008-06-24 11:03:29 0 d-------- C:\WINDOWS\Prefetch
    2008-06-24 11:03:28 229376 --a------ C:\Documents and Settings\LocalService\NTUSER.DAT
    2008-06-24 11:03:28 0 d--h----- C:\Documents and Settings\LocalService\Local Settings <LOCALS~1>
    2008-06-24 11:03:28 0 d---s---- C:\Documents and Settings\LocalService\Cookies
    2008-06-24 11:03:28 0 d-------- C:\Documents and Settings\LocalService\Application Data <APPLIC~1>
    2008-06-24 11:03:28 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
    2008-06-24 11:03:25 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings <LOCALS~1>
    2008-06-24 11:03:25 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
    2008-06-24 11:03:25 0 d-------- C:\Documents and Settings\NetworkService\Application Data <APPLIC~1>
    2008-06-24 11:03:25 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
    2008-06-24 11:03:24 229376 --a------ C:\Documents and Settings\NetworkService\NTUSER.DAT
    2008-06-24 11:01:27 0 d-------- C:\WINDOWS\system32\xircom
    2008-06-24 11:01:27 0 d-------- C:\Program Files\microsoft frontpage
    2008-06-24 11:01:21 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
    2008-06-24 11:01:12 0 -rahs---- C:\MSDOS.SYS
    2008-06-24 11:01:12 0 -rahs---- C:\IO.SYS
    2008-06-24 11:01:12 0 --a------ C:\CONFIG.SYS
    2008-06-24 11:01:12 0 --a------ C:\AUTOEXEC.BAT
    2008-06-24 11:00:36 0 d--hs---- C:\Documents and Settings\All Users\DRM
    2008-06-24 11:00:31 0 dr------- C:\WINDOWS\Offline Web Pages
    2008-06-24 11:00:31 0 d---s---- C:\WINDOWS\Downloaded Program Files
    2008-06-24 11:00:22 0 d--h----- C:\Program Files\WindowsUpdate
    2008-06-24 11:00:21 0 d-------- C:\Program Files\Online Services
    2008-06-24 11:00:10 0 d-------- C:\WINDOWS\system32\DirectX
    2008-06-24 10:59:42 0 d---s---- C:\WINDOWS\Tasks
    2008-06-24 10:59:40 0 d-------- C:\Program Files\Common Files\MSSoap
    2008-06-24 10:59:37 0 d-------- C:\WINDOWS\srchasst
    2008-06-24 10:59:36 0 d-------- C:\WINDOWS\system32\Macromed
    2008-06-24 10:59:30 0 d-------- C:\Program Files\Movie Maker
    2008-06-24 10:59:24 0 d-------- C:\WINDOWS\system32\Restore
    2008-06-24 10:58:56 21736 --a------ C:\WINDOWS\system32\emptyregdb.dat
    2008-06-24 10:58:46 0 d-------- C:\WINDOWS\Registration
    2008-06-24 10:58:37 0 d-------- C:\Program Files\Messenger
    2008-06-24 10:58:34 0 d-------- C:\Program Files\MSN Gaming Zone
    2008-06-24 10:58:08 0 d-------- C:\Program Files\Windows NT
    2008-06-24 10:58:05 0 d-------- C:\WINDOWS\system32\MsDtc
    2008-06-24 10:58:04 0 d-------- C:\WINDOWS\system32\Com


    -- Find3M Report ---------------------------------------------------------------

    2008-06-26 13:40:23 295192 --a------ C:\WINDOWS\system32\perfh01F.dat
    2008-06-26 13:40:23 43094 --a------ C:\WINDOWS\system32\perfc01F.dat
    2008-06-24 13:48:04 62 --ahs---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
    2008-05-16 14:01:00 1630208 --a------ C:\WINDOWS\system32\nwiz.exe
    2008-05-16 14:01:00 1019904 --a------ C:\WINDOWS\system32\nvwimg.dll
    2008-05-16 14:01:00 1703936 --a------ C:\WINDOWS\system32\nvwdmcpl.dll
    2008-05-16 14:01:00 466944 --a------ C:\WINDOWS\system32\nvshell.dll
    2008-05-16 14:01:00 1486848 --a------ C:\WINDOWS\system32\nview.dll
    2008-05-16 14:01:00 1339392 --a------ C:\WINDOWS\system32\nvdspsch.exe
    2008-05-16 14:01:00 442368 --a------ C:\WINDOWS\system32\nvappbar.exe
    2008-05-16 14:01:00 425984 --a------ C:\WINDOWS\system32\keystone.exe


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [18.12.2006 16:34]
    "SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [13.07.2006 07:12]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [16.05.2008 14:01]
    "nwiz"="nwiz.exe" [16.05.2008 14:01 C:\WINDOWS\system32\nwiz.exe]
    "AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [28.06.2007 12:51]
    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [16.05.2008 14:01]
    "FixCamera"="C:\WINDOWS\FixCamera.exe" [01.06.2006 11:26]
    "tsnp2std"="C:\WINDOWS\tsnp2std.exe" [19.06.2006 13:37]
    "snp2std"="C:\WINDOWS\vsnp2std.exe" [15.05.2006 15:52]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [04.08.2004 00:45]
    "Free Download Manager"="C:\Program Files\Free Download Manager\fdm.exe" [20.05.2008 17:27]
    "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [19.01.2007 12:55]

    C:\Documents and Settings\Administrator\Start Menu\Programlar\BaŸlang‡\
    Xfire.lnk - C:\Program Files\Xfire\xfire.exe [26.06.2008 23:10:40]

    C:\Documents and Settings\All Users\Start Menu\Programlar\BaŸlang‡\
    USRobotics Wireless USB Adapter.lnk - C:\Program Files\USRobotics\Wireless USB Manager\USR54G.exe [14.04.2006 14:18:30]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoFolderOptions"=0 (0x0)
    "LinkResolveIgnoreLinkInfo"=0 (0x0)
    "NoResolveSearch"=1 (0x1)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoFolderOptions"=0 (0x0)
    "LinkResolveIgnoreLinkInfo"=0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp




    -- End of Deckard's System Scanner: finished at 2008-07-05 14:13:01 ------------




  • arkadasim bu konuya degil diger konuya gonder lutfen analizleri. burasi genel tartisma bolumu
  • Eline sağlık
  • sağol @serji, sistem yavaşlamasından dolayı sürekli yeni konular açılıyor, bu konu pek çok kişiye faydalı olacaktır

    sormak istediğim hijackthis in kendi sitesinde (www.hijackthis.de ) logları otomatik analiz eden bir yazılım var, bu analizden aldığımız sonuç yeterlimidir buna güvenebilirmiyiz, yoksa otomatik olarak değerlendirme yapan bu yazılım bir takım zararlıları atlayabilirmi? teşekkürler
  • quote:

    Orjinalden alıntı: Danilo Thann
    Eline sağlık

    saolasin

    quote:

    Orjinalden alıntı: arkitrom
    sağol @serji, sistem yavaşlamasından dolayı sürekli yeni konular açılıyor, bu konu pek çok kişiye faydalı olacaktır

    sormak istediğim hijackthis in kendi sitesinde (www.hijackthis.de ) logları otomatik analiz eden bir yazılım var, bu analizden aldığımız sonuç yeterlimidir buna güvenebilirmiyiz, yoksa otomatik olarak değerlendirme yapan bu yazılım bir takım zararlıları atlayabilirmi? teşekkürler

    Herhangi bir yanlis tespit yapmaz. Yani eksisi yok ama artisi da fazla yok diyebilirim. Hani size faydali bir yazilimi silin demez ama cogu zaman akilli virusler dedigimiz kamufle edebilen virusleri de gormez. O yuzden cok cok acil bi durumolmadikca kullanilmasini pek tavsiye etmiyorum. Bu konuda gercekten bilgili ve uzman birine analizleri okutmak ve yardim almak cok daha akillica ve etkili olacaktir. Isteyen arkadaslar benim actigim konuya gonderebilirl.er




  • Eline Sağlık
  • Yapay Zeka’dan İlgili Konular
    Daha Fazla Göster
  • elinize sağlık hocam güzel bir paylaşım olmuş
  • quote:

    Orjinalden alıntı: 5kursun
    Eline Sağlık

    saolasin.
    quote:

    Orjinalden alıntı: cyber91
    elinize sağlık hocam güzel bir paylaşım olmuş

    saolasin dostm
  • Güzel Bilgi
  • quote:

    Orjinalden alıntı: ßy Spécops.
    Güzel Bilgi

    saolasin kolay gelsn
  • slm ben anti spyware aracı olarak spyware terminatörü kullanıorum sizce nası???
  • quote:

    Orjinalden alıntı: ibosh___

    slm ben anti spyware aracı olarak spyware terminatörü kullanıorum sizce nası???

    Guzel bir program. Fakat Bazi ozelliklerini aktif hale getirdiginizde -ozellikle vistada- performans sorunlarina yol acabailiyor.
  • eline sağlık güze paylasım
  • Paylaşım için sağol
  • quote:

    Orjinalden alıntı: CrAzYB0Y

    eline sağlık güze paylasım

    saolasin


    quote:

    Orjinalden alıntı: FAQ

    Paylaşım için sağol

    rca ederm dostm
  • Çok iyi oldu bu konu gerçekten.Programı kurdum.Tarama sonuçlarını birazdan gönderiyorum.
  • kimseyi takma dostum güzel paylaşım olmuş dewamını bekliyoruz
  • quote:

    Orjinalden alıntı: Nodex

    Çok iyi oldu bu konu gerçekten.Programı kurdum.Tarama sonuçlarını birazdan gönderiyorum.

    bekliyorum kolay gelsin.


    quote:

    Orjinalden alıntı: STuSS

    kimseyi takma dostum güzel paylaşım olmuş dewamını bekliyoruz

    saolasin dostm ins
  • bi arkadaşımın pcsindede yaptık

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:16:20, on 18.07.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\CMExplorer.exe
    C:\WINDOWS\system32\CmUCReye.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\FlashGet\FlashGet.exe
    C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe
    C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
    C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Logitech\SetPoint\KEM.exe
    C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\lxdiserv.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrB.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Opera\opera.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
    O1 - Hosts: 208.65.153.253www.youtube.com #25.03.2008
    O1 - Hosts: 208.65.153.253www.youtube.com #27.03.2008
    O1 - Hosts: 146.82.202.169www.pornhub.com #08.04.2008
    O1 - Hosts: 146.82.203.230www.pornhub.com #25.04.2008
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
    O2 - BHO: BrowsingEnhancer - {5ABBD91B-0215-2FE1-7A7E-753F05B40CB8} - C:\Program Files\BrowsingEnhancer\BrowsingEnhancer-2.dll (file missing)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Oturum Açma Yardım Aracı - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Mirar - {9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB55.dll (file missing)
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Mirar - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB55.dll (file missing)
    O4 - HKLM\..\Run: [CMExplorer] C:\WINDOWS\CMExplorer.exe
    O4 - HKLM\..\Run: [CmUCRRun] C:\WINDOWS\system32\CmUCReye.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidTool.exe boot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Flashget] "C:\Program Files\FlashGet\FlashGet.exe" /min
    O4 - HKLM\..\Run: [WhenUSearchWHSE] "C:\Program Files\DAEMON Tools SearchBar\whse.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [lxdimon.exe] "C:\Program Files\Lexmark 3500-4500 Series\lxdimon.exe"
    O4 - HKLM\..\Run: [lxdiamon] "C:\Program Files\Lexmark 3500-4500 Series\lxdiamon.exe"
    O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\\Lexmark Fax Solutions\fm3032.exe" /s
    O4 - HKLM\..\Run: [kis] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
    O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
    O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\\ie_banner_deny.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
    O9 - Extra button: Bunu Web Günlüğüne Al - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: Windows Live Writer içinde &Bunu Web Günlüğüne Al - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {D0BB3ACE-4ED3-4D65-BB86-1A0C6CAF351F} (AvaLaunch Control) -http://212.175.239.246:81/avaLaunch94.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{9EC02BC2-12C3-43F5-8433-065908CC0565}: NameServer = 208.67.222.222,208.67.220.220
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = cc.metu.edu.tr,metu.edu.tr
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = cc.metu.edu.tr,metu.edu.tr
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = cc.metu.edu.tr,metu.edu.tr
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
    O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: lxdiCATSCustConnectService - Lexmark International, Inc. - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdiserv.exe
    O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PunkBuster (PnkBstrA) - Unknown owner - D:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\MOHAGame\pb\PnkBstrA.exe (file missing)
    O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe

    --
    End of file - 9093 bytes

    ve bunlar var hangilerini kaldırcaz performans artışı için




  • 
Sayfa: 12
Sayfaya Git
Git
sonraki
- x
Bildirim
mesajınız kopyalandı (ctrl+v) yapıştırmak istediğiniz yere yapıştırabilirsiniz.