rambo123 | 03.04.2014 14:35 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 03.04.2014
Suchlauf-Zeit: 14:27:13
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.04.03.02
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Esra Kĵcĵkvaruzan
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 271205
Verstrichene Zeit: 40 Min, 7 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Warnen
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 6
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [0cf4ca36c0407b8561a08d01aa59ba46],
PUP.Optional.DoSearch.A, HKLM\SOFTWARE\WOW6432NODE\do-searchSoftware, In Quarantäne, [956bd72901ff4ab6a3a0b7b145bdaa56],
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, In Quarantäne, [ed13b848ac5416ea946dd8b618ebfa06],
PUP.Optional.InstallBrain.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT, In Quarantäne, [ae529b65ac543dc374dd9bee778ce41c],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3754061674-2540918322-2663123439-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [43bd78889b658d731ad397d4847ed52b],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3754061674-2540918322-2663123439-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [ec1437c9b64a3bc536f992f0bf4422de],
Registrierungswerte: 6
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{336D0C35-8A85-403a-B9D2-65C292C39087}, In Quarantäne, [21df748c17e9b749d940cf3b4cb60af6],
PUP.Optional.HomePageProtector.A, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{336D0C35-8A85-403A-B9D2-65C292C39087}, C:\Program Files\IB Updater\Firefox, In Quarantäne, [21df748c17e9b749d940cf3b4cb60af6]
PUP.Optional.Incredibar, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{FE1DEEEA-DB6D-44b8-83F0-34FC0F9D1052}, C:\Program Files\IB Updater\Firefox, In Quarantäne, [bb45c73927d9a75979544b42d231d729]
PUP.Optional.InstallBrain.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WNLT|URL, In Quarantäne, [ae529b65ac543dc374dd9bee778ce41c],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3754061674-2540918322-2663123439-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0E1M2W0U1T, In Quarantäne, [ec1437c9b64a3bc536f992f0bf4422de]
PUP.Optional.SpeedupmyComputer, HKU\S-1-5-21-3754061674-2540918322-2663123439-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|SpeedUpMyComputer, C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe /ot /as, In Quarantäne, [c040d42cfc0419e738b374e0b84a12ee]
Registrierungsdaten: 4
PUP.Optional.DoSearch.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://do-search.com/web/?type=ds&ts=1385381950&from=smt&uid=WDCXWD5000BPVT-55A1YT0_WD-WX31C32K3268K3268&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://do-search.com/web/?type=ds&ts=1385381950&from=smt&uid=WDCXWD5000BPVT-55A1YT0_WD-WX31C32K3268K3268&q={searchTerms}),Ersetzt,[b749de226d93d8283b2327eb22e2bd43]
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[699789777888e02044f76ca6758f49b7]
PUP.Optional.DoSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://do-search.com/web/?type=ds&ts=1385381950&from=smt&uid=WDCXWD5000BPVT-55A1YT0_WD-WX31C32K3268K3268&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://do-search.com/web/?type=ds&ts=1385381950&from=smt&uid=WDCXWD5000BPVT-55A1YT0_WD-WX31C32K3268K3268&q={searchTerms}),Ersetzt,[6799ce32d12f6b951846cc46a1630000]
PUP.Optional.Qone8, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[f30d768a7c84e61afd3ea17109fbfd03]
Ordner: 1
PUP.Optional.SpeedupmyComputer, C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer, In Quarantäne, [c040d42cfc0419e738b374e0b84a12ee],
Dateien: 22
PUP.Optional.Iminent.A, C:\Users\Esra Kĵcĵkvaruzan\Desktop\bootstrapper.exe, In Quarantäne, [09f7fe0221dfcc348a694bda1fe28f71],
PUP.Optional.Somoto.A, C:\$Recycle.Bin\S-1-5-21-3754061674-2540918322-2663123439-1002\$R4R2E1J\biclient.exe, In Quarantäne, [c13fd52b986843bd0224a76952af24dc],
PUP.Optional.Somoto, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Temp\UpdateCheckerSetup.exe, In Quarantäne, [1ce454ac0af61be532bc190d44bcc33d],
PUP.Optional.SmartTweak, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Temp\SpeedUpMyComputer.exe, In Quarantäne, [dc24b34d26dadb2515ff93564db6f60a],
PUP.Optional.SkyTech.A, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Temp\smt_do-search_201311131701.exe, In Quarantäne, [e51b788808f86a96fe9b0b4357aa8977],
PUP.Optional.NationZoom.A, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Temp\MircosoftStudio\Baofeng.exe, In Quarantäne, [ec14e41cc937fd039dca5fce7e829967],
PUP.Optional.NationZoom.A, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Temp\MircosoftStudio\package1.zip, In Quarantäne, [7b85e917bc448e72590e939a36caed13],
PUP.Optional.NationZoom.A, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Temp\fullpackage_temp\Baofeng.exe, In Quarantäne, [c739d22e90702dd302653bf2ea16dd23],
PUP.Optional.NationZoom.A, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Temp\fullpackage_temp\package1.zip, In Quarantäne, [be422fd121df8f711552ad801ce4d12f],
PUP.Optional.Crimsolite.A, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Temp\is1590112554\21777960_stp\setup.exe, In Quarantäne, [b848f907e020ef11034158a3a65d23dd],
PUP.Optional.InstallCore.A, C:\Users\Esra Kĵcĵkvaruzan\Downloads\setup.exe, In Quarantäne, [f50bed1347b910f06405c740c73a837d],
PUP.Optional.Softonic.A, C:\Users\Esra Kĵcĵkvaruzan\Downloads\SoftonicDownloader_fuer_codedcolor-fotostudio.exe, In Quarantäne, [4bb54fb1d62a89773d27c355907120e0],
PUP.Optional.Softonic, C:\Users\Esra Kĵcĵkvaruzan\Downloads\SoftonicDownloader_fuer_free-youtube-download.exe, In Quarantäne, [966a55ab36caaf51bb4ad924e818ba46],
PUP.Optional.Conduit.A, C:\Users\Esra Kĵcĵkvaruzan\Downloads\PDFssoftware.exe, In Quarantäne, [7888718f52ae08f8854c4cf64eb36f91],
Adware.InstallBrain, C:\Users\Esra Kĵcĵkvaruzan\Downloads\VideoPerformerSetup.exe, In Quarantäne, [eb15cf316799e020f92654acf1101ae6],
PUP.Optional.InstallCore, C:\Users\Esra Kĵcĵkvaruzan\Downloads\ZipOpenerSetup.exe, In Quarantäne, [659b24dc56aa9f61104dae58976a8a76],
PUP.Optional.Somoto, C:\Users\Esra Kĵcĵkvaruzan\Downloads\ChinaTown_downloader_by_SchriftartenFontsde.exe, In Quarantäne, [b44cd42cb64aa55bff9e37fde4202ed2],
PUP.BundleInstaller.DW, C:\Users\Esra Kĵcĵkvaruzan\Downloads\codec_pack_54410_ch.exe, In Quarantäne, [f30de020ba460ef297549765e31d6a96],
PUP.Optional.CrossRider.A, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0.localstorage, In Quarantäne, [c739936db050ea1675816bf07191b947],
PUP.Optional.CrossRider.A, C:\Users\Esra Kĵcĵkvaruzan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_omfoidjpeklpjhlhabhcomekbkclkbec_0.localstorage-journal, In Quarantäne, [5fa1a25e19e7f40c03f376e5e61c01ff],
PUP.Optional.SpeedupmyComputer, C:\Program Files (x86)\SmartTweak\SpeedUpMyComputer\SpeedUpMyComputer.exe, In Quarantäne, [c040d42cfc0419e738b374e0b84a12ee],
PUP.Optional.CrossRider.A, C:\Users\Esra Kĵcĵkvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "13f6172378f9208ce7e759163315f1a6");), Ersetzt,[a060649cd828c0408cc4b389f11345bb]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.023 - Bericht erstellt am 03/04/2014 um 14:47:11
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Esra Kücükvaruzan - ESRAKÜCÜKVARUZA
# Gestartet von : C:\Users\Esra Kücükvaruzan\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Yandex
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\open it!
Ordner Gelöscht : C:\Program Files (x86)\openit
Ordner Gelöscht : C:\Program Files (x86)\Yandex
Ordner Gelöscht : C:\Users\ESRAKC~1\AppData\Local\Temp\Mega Browse
Ordner Gelöscht : C:\Users\Esra Kücükvaruzan\AppData\LocalLow\Yandex
Ordner Gelöscht : C:\Users\Esra Kücükvaruzan\AppData\Roaming\DigitalSites
Ordner Gelöscht : C:\Users\Esra Kücükvaruzan\AppData\Roaming\Yandex
Ordner Gelöscht : C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\Yandex
Datei Gelöscht : C:\Users\Public\Desktop\Open It!.lnk
Datei Gelöscht : C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\invalidprefs.js
Datei Gelöscht : C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\user.js
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\user.js
Datei Gelöscht : C:\Users\Esra Kücükvaruzan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ifohbjbgfchkkfhphahclmkpgejiplfo_0.localstorage
Datei Gelöscht : C:\Users\Esra Kücükvaruzan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage
Datei Gelöscht : C:\Users\Esra Kücükvaruzan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_igdhbblpcellaljokkpfhcjlagemhgjl_0.localstorage-journal
Datei Gelöscht : C:\Windows\System32\Tasks\Dealply
Datei Gelöscht : C:\Windows\System32\Tasks\DealPlyUpdate
Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater
Datei Gelöscht : C:\Windows\System32\Tasks\Funmoods
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_gimp_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_gimp_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C17A0751-580B-466B-8271-5C73EFDC1295}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355345526}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366346626}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C17A0751-580B-466B-8271-5C73EFDC1295}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550355345526}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660366346626}
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\performersoft llc
Schlüssel Gelöscht : HKCU\Software\smarttweak
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKLM\Software\hdcode
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\openit open it!
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\IB Updater
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v27.0.1 (de)
[ Datei : C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.vb@yandex.ru.alienAddonRecords", "{\"hxxp://do-search.com/newtab/?type=nt&ts=1385381950&from=smt&uid=WDCXWD5000BPVT-55A1YT0_WD-WX31C32K3268K3268\":0}");
Zeile gelöscht : user_pref("extensions.vb@yandex.ru.browser.alien.newtab.url", "hxxp://do-search.com/newtab/?type=nt&ts=1385381950&from=smt&uid=WDCXWD5000BPVT-55A1YT0_WD-WX31C32K3268K3268");
Zeile gelöscht : user_pref("extensions.vb@yandex.ru.description", "Keep all your favorite sites in one place with Visual Bookmarks. Simply click on one of the mini-webpages to visit a site. You can customize the numbe[...]
-\\ Google Chrome v33.0.1750.154
[ Datei : C:\Users\Esra Kücükvaruzan\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [5644 octets] - [03/04/2014 14:42:51]
AdwCleaner[S0].txt - [5070 octets] - [03/04/2014 14:47:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5130 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by Esra Kckvaruzan on 03.04.2014 at 14:54:00,84
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3754061674-2540918322-2663123439-1002\Software\ib updater
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3754061674-2540918322-2663123439-1002\Software\sweetim
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Esra Kckvaruzan\AppData\Roaming\zip opener packages"
Successfully deleted: [Folder] "C:\Program Files (x86)\smarttweak"
Successfully deleted: [Folder] "C:\Users\Esra Kckvaruzan\AppData\Roaming\microsoft\windows\start menu\programs\smarttweak software"
Successfully deleted: [Empty Folder] C:\Users\Esra Kckvaruzan\appdata\local\{26416407-BC29-47D2-A66B-2177E429E179}
Successfully deleted: [Empty Folder] C:\Users\Esra Kckvaruzan\appdata\local\{2ADC44DD-2A36-4AA0-A182-CBC76BF38969}
Successfully deleted: [Empty Folder] C:\Users\Esra Kckvaruzan\appdata\local\{5D165EFA-D14C-4D5A-8BDC-4B84F1318F11}
~~~ FireFox
Emptied folder: C:\Users\Esra Kckvaruzan\AppData\Roaming\mozilla\firefox\profiles\zzchadsu.default\minidumps [40 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.04.2014 at 15:31:08,50
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Esra Kücükvaruzan (administrator) on ESRAKÜCÜKVARUZA on 03-04-2014 15:33:33
Running from C:\Users\Esra Kücükvaruzan\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Advanced Micro Devices, Inc.) c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Windows\system32\mfevtps.exe
(Sony Corporation) c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Facebook Inc.) C:\Users\Esra Kücükvaruzan\AppData\Local\Facebook\Update\FacebookUpdate.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Advanced Micro Devices Inc.) c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update Common\VUAgent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAdmin.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Improvement\vim.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1158248 2012-04-12] (Realtek Semiconductor)
HKLM\...\Run: [AtherosBtStack] - C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [1021056 2012-03-29] (Atheros Communications)
HKLM\...\Run: [AthBtTray] - C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [801408 2012-03-29] (Atheros Commnucations)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2890000 2012-04-12] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] - c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [343168 2012-03-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ISBMgr.exe] - C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [60552 2011-09-20] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] - c:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [693608 2012-02-21] (Sony Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-09-17] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3754061674-2540918322-2663123439-1002\...\Run: [Facebook Update] - C:\Users\Esra Kücükvaruzan\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-01-06] (Facebook Inc.)
HKU\S-1-5-21-3754061674-2540918322-2663123439-1002\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [18705664 2013-01-08] (Skype Technologies S.A.)
HKU\S-1-5-21-3754061674-2540918322-2663123439-1002\...\Run: [SkyDrive] - C:\Users\Esra Kücükvaruzan\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [257224 2014-02-21] (Microsoft Corporation)
HKU\S-1-5-21-3754061674-2540918322-2663123439-1002\...\Run: [GoogleChromeAutoLaunch_ED15468D70D5DD7096A13FA4A8B9A86D] - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [859976 2014-03-15] (Google Inc.)
HKU\S-1-5-21-3754061674-2540918322-2663123439-1002\...\Run: [YandexElements] - "C:\Program Files (x86)\Yandex\Common\elements64.exe" /auto
HKU\S-1-5-21-3754061674-2540918322-2663123439-1002\...\RunOnce: [Uninstall C:\Users\Esra Kücükvaruzan\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\amd64] - C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Esra Kücükvaruzan\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530\amd64"
HKU\S-1-5-21-3754061674-2540918322-2663123439-1002\...\RunOnce: [Uninstall C:\Users\Esra Kücükvaruzan\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530] - C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Esra Kücükvaruzan\AppData\Local\Microsoft\SkyDrive\17.0.2010.0530"
HKU\S-1-5-21-3754061674-2540918322-2663123439-1002\...\RunOnce: [Uninstall C:\Users\Esra Kücükvaruzan\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64] - C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Esra Kücükvaruzan\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811\amd64"
HKU\S-1-5-21-3754061674-2540918322-2663123439-1002\...\RunOnce: [Uninstall C:\Users\Esra Kücükvaruzan\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811] - C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Esra Kücükvaruzan\AppData\Local\Microsoft\SkyDrive\17.0.2015.0811"
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://sony.msn.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKCU - 4E92B0BAF236F2CA6C075C90FA5EBCE8 URL = hxxp://gorsel.yandex.com.tr/yandsearch?win=118&clid=1989274&text={searchTerms}
SearchScopes: HKCU - 583F5D78D03D8B7344E3815EC4E318E3 URL = hxxp://video.yandex.com.tr/#search?win=118&clid=1989274&text={searchTerms}
SearchScopes: HKCU - 863B74D4DCDD01EB1E2D52ADEAC89031 URL = hxxp://do-search.com/web/?type=ds&ts=1385381950&from=smt&uid=WDCXWD5000BPVT-55A1YT0_WD-WX31C32K3268K3268&q={searchTerms}
SearchScopes: HKCU - DA2A584F87DFC9F4F1057626386E81A9 URL = hxxp://haber.yandex.com.tr/yandsearch?rpt=nnews2&grhow=clutop&win=118&clid=1989274&text={searchTerms}
SearchScopes: HKCU - {CFAE870E-EB2E-4455-96C0-4CE78E858158} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-Q212&_nkw={searchTerms}
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120510062228.dll (McAfee, Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Визуальные закладки - {D5FEC983-01DB-414a-9456-AF95AC9ED7B5} - C:\Program Files (x86)\Yandex\FastDial\fastdial64Host.dll No File
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120510062228.dll (McAfee, Inc.)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Визуальные закладки - {D5FEC983-01DB-414a-9456-AF95AC9ED7B5} - C:\Program Files (x86)\Yandex\FastDial\fastdialHost.dll No File
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - Yandex Elements - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files (x86)\Yandex\Elements\bartab64host.dll No File
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Yandex Elements - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files (x86)\Yandex\Elements\bartabhost.dll No File
Toolbar: HKCU - Yandex Elements - {91397D20-1446-11D4-8AF4-0040CA1127B6} - C:\Program Files (x86)\Yandex\Elements\bartab64host.dll No File
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{01A9B807-333C-40A4-980F-BF4E52C9E206}: [NameServer]8.8.4.4,8.8.8.8
FireFox:
========
FF ProfilePath: C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Esra Kücükvaruzan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\searchplugins\gorsel.yandex.com.tr-193909.xml
FF SearchPlugin: C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\searchplugins\haber.yandex.com.tr-193909.xml
FF SearchPlugin: C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\searchplugins\video.yandex.com.tr-193909.xml
FF SearchPlugin: C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\searchplugins\yandex.com.tr-193909.xml
FF SearchPlugin: C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\searchplugins\yqs-barff-yagorsel.xml
FF SearchPlugin: C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\searchplugins\yqs-barff-yahaber.xml
FF SearchPlugin: C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\searchplugins\yqs-barff-yandex.xml
FF SearchPlugin: C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\searchplugins\yqs-barff-yavideo.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Візуальныя закладкі - C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\Extensions\vb@yandex.ru [2014-04-01]
FF Extension: Кампанент "Элементы Яндекса" - C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\Extensions\yasearch@yandex.ru [2014-04-01]
FF Extension: Adblock Plus - C:\Users\Esra Kücükvaruzan\AppData\Roaming\Mozilla\Firefox\Profiles\zzchadsu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-03-28]
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore
FF Extension: No Name - C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012-05-10]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2012-05-10]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2012-05-10]
Chrome:
=======
CHR DefaultSearchKeyword: yandex.com.tr
CHR DefaultSearchProvider: Yandex
CHR DefaultSearchURL: hxxp://yandex.com.tr/yandsearch?win=118&clid=1989274&text={searchTerms}
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U13) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
CHR Plugin: (Media Go Detector) - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
CHR Plugin: (PlayStation(R)Network Downloader Check Plug-in) - C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\Esra Kücükvaruzan\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.130.20) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (ZenMate for Google Chrome™) - C:\Users\Esra Kücükvaruzan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-03-24]
CHR Extension: (SiteAdvisor) - C:\Users\Esra Kücükvaruzan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-06-21]
CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\Esra Kücükvaruzan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2013-06-21]
CHR Extension: (Google Wallet) - C:\Users\Esra Kücükvaruzan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2012-12-22]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2013-01-30]
==================== Services (Whitelisted) =================
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AMD FUEL Service; c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-03-06] (Advanced Micro Devices, Inc.)
S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [112256 2012-03-21] (Atheros Communication Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation)
S4 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S4 McAWFwk; C:\Program Files\McAfee\MSC\McAWFwk.exe [225216 2011-01-28] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S4 mcmscsvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S4 McNaiAnn; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S4 McNASvc; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S4 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [383608 2012-11-16] (McAfee, Inc.)
S4 McOobeSv; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
S4 McProxy; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [241016 2012-11-09] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [218320 2012-11-09] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [177680 2012-11-09] (McAfee, Inc.)
S4 MOBK649backup; C:\Program Files (x86)\McAfee Online Backup\MOBK649backup.exe [223544 2011-04-18] (McAfee, Inc.)
S4 MSK80Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.)
R2 PMBDeviceInfoProvider; c:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [473960 2012-02-21] (Sony Corporation)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [260768 2011-11-30] (Sony Corporation)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [960160 2011-12-29] (Sony Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [163456 2012-03-29] (Atheros)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [69672 2012-11-09] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [196440 2012-04-20] (McAfee, Inc.)
S3 lehidmini; C:\Windows\system32\drivers\leath_hid.sys [36608 2012-03-29] (Atheros)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-03-05] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [119512 2014-04-03] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-03-05] (Malwarebytes Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [178840 2012-11-09] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [309400 2012-11-09] (McAfee, Inc.)
U3 mfeavfk01; No ImagePath
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [515528 2012-11-09] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [771096 2012-11-09] (McAfee, Inc.)
S3 mferkdet; C:\Windows\System32\drivers\mferkdet.sys [106112 2012-11-09] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [339776 2012-11-09] (McAfee, Inc.)
R1 MOBK649Filter; C:\Windows\System32\DRIVERS\MOBK649.sys [66040 2011-04-18] (Mozy, Inc.)
S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver.sys [21264 2012-04-12] (Synaptics Incorporated)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-03 15:31 - 2014-04-03 15:31 - 00001919 _____ () C:\Users\Esra Kücükvaruzan\Desktop\JRT.txt
2014-04-03 14:53 - 2014-04-03 14:53 - 01038974 _____ (Thisisu) C:\Users\Esra Kücükvaruzan\Downloads\JRT.exe
2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ___RD () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-04-03 14:42 - 2014-04-03 14:48 - 00000000 ____D () C:\AdwCleaner
2014-04-03 14:41 - 2014-04-03 14:42 - 01426178 _____ () C:\Users\Esra Kücükvaruzan\Downloads\adwcleaner.exe
2014-04-03 14:39 - 2014-04-03 14:39 - 00008446 _____ () C:\Users\Esra Kücükvaruzan\Desktop\mbam.txt
2014-04-03 13:43 - 2014-04-03 14:52 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-03 13:42 - 2014-04-03 13:42 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-03 13:42 - 2014-04-03 13:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-03 13:42 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 13:42 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 13:40 - 2014-04-03 13:41 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Esra Kücükvaruzan\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-02 19:29 - 2014-04-02 19:29 - 00001268 _____ () C:\Users\Esra Kücükvaruzan\Desktop\Revo Uninstaller.lnk
2014-04-02 19:29 - 2014-04-02 19:29 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-02 19:28 - 2014-04-02 19:28 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Esra Kücükvaruzan\Downloads\revosetup95.exe
2014-03-31 20:55 - 2014-04-03 00:55 - 00000039 _____ () C:\Users\Esra Kücükvaruzan\AppData\Roaming\WB.CFG
2014-03-31 20:27 - 2014-03-31 20:31 - 00048578 _____ () C:\Users\Esra Kücükvaruzan\Downloads\Addition.txt
2014-03-31 20:24 - 2014-04-03 15:33 - 00028603 _____ () C:\Users\Esra Kücükvaruzan\Downloads\FRST.txt
2014-03-31 20:24 - 2014-04-03 15:33 - 00000000 ____D () C:\FRST
2014-03-31 20:22 - 2014-03-31 20:22 - 02157056 _____ (Farbar) C:\Users\Esra Kücükvaruzan\Downloads\FRST64.exe
2014-03-31 19:57 - 2014-04-03 13:29 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Roaming\AnySend
2014-03-31 19:57 - 2014-04-03 13:29 - 00000000 ____D () C:\ProgramData\AnySend
2014-03-31 19:39 - 2014-03-31 19:39 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Opera Software
2014-03-31 19:39 - 2014-03-31 19:39 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Opera
2014-03-31 19:39 - 2014-03-31 19:39 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Local\Opera
2014-03-31 19:39 - 2014-03-31 19:39 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Local\Chromium
2014-03-31 19:35 - 2014-03-31 19:35 - 00686720 _____ () C:\Users\Esra Kücükvaruzan\Downloads\ZipExtractorSetup.exe
2014-03-24 20:51 - 2014-03-24 20:52 - 08566128 _____ (CyberGhost S.R.L. ) C:\Users\Esra Kücükvaruzan\Downloads\CG_5.0.9.8chip.de.exe
2014-03-19 20:04 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-19 20:04 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-19 20:04 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-19 20:04 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-19 20:04 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-19 20:04 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-19 20:04 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-19 20:04 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-19 20:04 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-19 20:04 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-19 20:04 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-19 20:04 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-19 20:04 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-19 20:04 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-19 20:04 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-19 20:04 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-19 20:04 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-19 20:04 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-19 20:04 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-19 20:04 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-19 20:04 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-19 20:04 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-19 20:04 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-19 20:04 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-19 20:04 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-19 20:04 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-19 20:04 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-19 20:04 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-19 20:04 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-19 20:04 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-19 20:04 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-19 20:04 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-19 20:04 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-19 20:04 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-19 20:04 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-19 20:04 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-19 20:04 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-19 20:04 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-19 20:04 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-19 20:04 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-14 21:27 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-14 21:27 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-14 21:27 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-14 21:27 - 2014-01-28 04:32 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-03-14 21:22 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-14 21:22 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-14 21:21 - 2014-02-04 04:32 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-03-14 21:21 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-03-14 20:12 - 2014-03-14 20:12 - 00000000 ____D () C:\Update
2014-03-10 00:05 - 2014-03-10 00:05 - 00230912 _____ (videoplayer.co.uk) C:\Users\Esra Kücükvaruzan\Downloads\Filmi_.izle (3).exe
2014-03-10 00:04 - 2014-03-10 00:04 - 00230912 _____ (videoplayer.co.uk) C:\Users\Esra Kücükvaruzan\Downloads\Filmi_.izle.exe
2014-03-10 00:04 - 2014-03-10 00:04 - 00230912 _____ (videoplayer.co.uk) C:\Users\Esra Kücükvaruzan\Downloads\Filmi_.izle (2).exe
2014-03-10 00:04 - 2014-03-10 00:04 - 00230912 _____ (videoplayer.co.uk) C:\Users\Esra Kücükvaruzan\Downloads\Filmi_.izle (1).exe
==================== One Month Modified Files and Folders =======
2014-04-03 15:34 - 2014-03-31 20:24 - 00028603 _____ () C:\Users\Esra Kücükvaruzan\Downloads\FRST.txt
2014-04-03 15:34 - 2013-01-11 16:01 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Skype
2014-04-03 15:33 - 2014-03-31 20:24 - 00000000 ____D () C:\FRST
2014-04-03 15:31 - 2014-04-03 15:31 - 00001919 _____ () C:\Users\Esra Kücükvaruzan\Desktop\JRT.txt
2014-04-03 15:00 - 2012-05-10 06:42 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-03 14:58 - 2009-07-14 06:45 - 00020928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-03 14:58 - 2009-07-14 06:45 - 00020928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-03 14:56 - 2012-05-10 06:46 - 00699666 _____ () C:\Windows\system32\perfh007.dat
2014-04-03 14:56 - 2012-05-10 06:46 - 00149774 _____ () C:\Windows\system32\perfc007.dat
2014-04-03 14:56 - 2009-07-14 07:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-03 14:55 - 2012-12-12 06:07 - 01161687 _____ () C:\Windows\WindowsUpdate.log
2014-04-03 14:53 - 2014-04-03 14:53 - 01038974 _____ (Thisisu) C:\Users\Esra Kücükvaruzan\Downloads\JRT.exe
2014-04-03 14:53 - 2013-06-24 17:26 - 00000000 ____D () C:\Windows\ERUNT
2014-04-03 14:52 - 2014-04-03 13:43 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-03 14:50 - 2014-04-03 14:50 - 00000000 ___RD () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-04-03 14:50 - 2012-12-18 15:47 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-03 14:49 - 2010-11-21 05:47 - 00202932 _____ () C:\Windows\PFRO.log
2014-04-03 14:49 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-03 14:49 - 2009-07-14 06:51 - 00096051 _____ () C:\Windows\setupact.log
2014-04-03 14:48 - 2014-04-03 14:42 - 00000000 ____D () C:\AdwCleaner
2014-04-03 14:47 - 2014-02-17 12:53 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-03 14:47 - 2012-12-18 15:47 - 00001132 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-03 14:42 - 2014-04-03 14:41 - 01426178 _____ () C:\Users\Esra Kücükvaruzan\Downloads\adwcleaner.exe
2014-04-03 14:39 - 2014-04-03 14:39 - 00008446 _____ () C:\Users\Esra Kücükvaruzan\Desktop\mbam.txt
2014-04-03 14:29 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\IME
2014-04-03 13:42 - 2014-04-03 13:42 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-03 13:42 - 2014-04-03 13:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-03 13:42 - 2013-06-22 11:04 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-03 13:41 - 2014-04-03 13:40 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Esra Kücükvaruzan\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-03 13:29 - 2014-03-31 19:57 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Roaming\AnySend
2014-04-03 13:29 - 2014-03-31 19:57 - 00000000 ____D () C:\ProgramData\AnySend
2014-04-03 12:52 - 2013-03-28 10:10 - 00001151 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-03 12:52 - 2012-12-18 15:48 - 00002251 _____ () C:\Users\Esra Kücükvaruzan\Desktop\google chrome.lnk
2014-04-03 12:52 - 2012-12-18 15:30 - 00001425 _____ () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-03 03:24 - 2012-05-10 06:59 - 00000000 ____D () C:\ProgramData\Skype
2014-04-03 00:55 - 2014-03-31 20:55 - 00000039 _____ () C:\Users\Esra Kücükvaruzan\AppData\Roaming\WB.CFG
2014-04-02 19:29 - 2014-04-02 19:29 - 00001268 _____ () C:\Users\Esra Kücükvaruzan\Desktop\Revo Uninstaller.lnk
2014-04-02 19:29 - 2014-04-02 19:29 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-02 19:28 - 2014-04-02 19:28 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Esra Kücükvaruzan\Downloads\revosetup95.exe
2014-03-31 20:31 - 2014-03-31 20:27 - 00048578 _____ () C:\Users\Esra Kücükvaruzan\Downloads\Addition.txt
2014-03-31 20:22 - 2014-03-31 20:22 - 02157056 _____ (Farbar) C:\Users\Esra Kücükvaruzan\Downloads\FRST64.exe
2014-03-31 19:39 - 2014-03-31 19:39 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Opera Software
2014-03-31 19:39 - 2014-03-31 19:39 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Opera
2014-03-31 19:39 - 2014-03-31 19:39 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Local\Opera
2014-03-31 19:39 - 2014-03-31 19:39 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Local\Chromium
2014-03-31 19:35 - 2014-03-31 19:35 - 00686720 _____ () C:\Users\Esra Kücükvaruzan\Downloads\ZipExtractorSetup.exe
2014-03-30 17:37 - 2013-01-25 14:50 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Local\CrashDumps
2014-03-29 03:00 - 2013-11-11 15:41 - 00000382 _____ () C:\Windows\Tasks\Quark Updater.job
2014-03-29 00:42 - 2012-12-18 15:47 - 00004128 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-03-29 00:42 - 2012-12-18 15:47 - 00003876 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-03-24 20:52 - 2014-03-24 20:51 - 08566128 _____ (CyberGhost S.R.L. ) C:\Users\Esra Kücükvaruzan\Downloads\CG_5.0.9.8chip.de.exe
2014-03-19 20:30 - 2009-07-14 06:45 - 00402104 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-19 20:29 - 2013-03-14 09:16 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-19 20:29 - 2013-03-14 09:16 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-03-19 20:03 - 2012-05-10 06:42 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-19 20:03 - 2012-05-10 06:42 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-19 20:03 - 2012-05-10 06:42 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-14 21:13 - 2012-12-18 15:29 - 00000000 ____D () C:\Users\Esra Kücükvaruzan
2014-03-14 21:11 - 2012-05-10 06:06 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite
2014-03-14 21:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system
2014-03-14 21:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\servicing
2014-03-14 21:09 - 2012-02-24 06:01 - 00000000 ____D () C:\Program Files\Windows Journal
2014-03-14 21:09 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-03-14 21:09 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-03-14 21:09 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-03-14 21:09 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Windows Defender
2014-03-14 21:09 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\DVD Maker
2014-03-14 21:09 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Portable Devices
2014-03-14 21:09 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-03-14 21:09 - 2009-07-14 05:20 - 00000000 __RSD () C:\Windows\Media
2014-03-14 21:09 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Public\Libraries
2014-03-14 21:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\migwiz
2014-03-14 21:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\L2Schemas
2014-03-14 21:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Cursors
2014-03-14 21:09 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\System
2014-03-14 21:08 - 2013-09-29 17:35 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-03-14 21:08 - 2013-06-17 23:12 - 00000000 ____D () C:\Program Files\Bonjour
2014-03-14 21:08 - 2013-06-17 23:12 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-03-14 21:08 - 2013-02-09 21:52 - 00000000 ____D () C:\Program Files (x86)\PhotoScape
2014-03-14 21:08 - 2013-01-11 16:01 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-14 21:08 - 2013-01-08 20:55 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\AppData\Roaming\dl_0
2014-03-14 21:08 - 2012-12-18 15:29 - 00000000 ___RD () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-03-14 21:08 - 2012-12-18 15:29 - 00000000 ___RD () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-03-14 21:08 - 2012-12-18 15:29 - 00000000 ___RD () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-03-14 21:08 - 2012-12-18 15:29 - 00000000 ___RD () C:\Users\Esra Kücükvaruzan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-03-14 21:08 - 2012-05-10 06:42 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-14 21:08 - 2012-05-10 06:21 - 00000000 ____D () C:\Program Files (x86)\McAfee Online Backup
2014-03-14 21:08 - 2012-05-10 06:13 - 00000000 ____D () C:\Program Files (x86)\Qualcomm Atheros WiFi Driver Installation
2014-03-14 21:08 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\restore
2014-03-14 21:08 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-03-14 21:06 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-03-14 20:12 - 2014-03-14 20:12 - 00000000 ____D () C:\Update
2014-03-10 00:05 - 2014-03-10 00:05 - 00230912 _____ (videoplayer.co.uk) C:\Users\Esra Kücükvaruzan\Downloads\Filmi_.izle (3).exe
2014-03-10 00:04 - 2014-03-10 00:04 - 00230912 _____ (videoplayer.co.uk) C:\Users\Esra Kücükvaruzan\Downloads\Filmi_.izle.exe
2014-03-10 00:04 - 2014-03-10 00:04 - 00230912 _____ (videoplayer.co.uk) C:\Users\Esra Kücükvaruzan\Downloads\Filmi_.izle (2).exe
2014-03-10 00:04 - 2014-03-10 00:04 - 00230912 _____ (videoplayer.co.uk) C:\Users\Esra Kücükvaruzan\Downloads\Filmi_.izle (1).exe
2014-03-09 01:14 - 2013-12-16 20:38 - 00000000 ____D () C:\Users\Esra Kücükvaruzan\Documents\Meine Weltreise
2014-03-05 09:26 - 2014-04-03 13:42 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-04-03 13:42 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2013-06-22 11:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
Some content of TEMP:
====================
C:\Users\Esra Kücükvaruzan\AppData\Local\Temp\bi_cleaner.exe
C:\Users\Esra Kücükvaruzan\AppData\Local\Temp\Quarantine.exe
C:\Users\Esra Kücükvaruzan\AppData\Local\Temp\{05D225D0-EC81-4163-B3E7-6C5152D17BAA}-29.0.1547.66_chrome_installer.exe
C:\Users\Esra Kücükvaruzan\AppData\Local\Temp\{361B4DC9-47EE-4840-B598-AFF71987DC56}-30.0.1599.69_chrome_installer.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-15 11:07
==================== End Of Log ============================ --- --- ---
--- --- --- |