bu Combofix log'um
ComboFix 10-08-22.03 - Admin 23.08.2010 2:24.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1254.90.1055.18.511.167 [GMT 3:00]
Running from: c:\documents and settings\Admin\Desktop\18628-ComboFix-190810.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Admin\Sık Kullanılanlar\# netbiLgini ~ en hızLı büyüyen forum...url
c:\documents and settings\Admin\Sık Kullanılanlar\7-24 New PVP Server 78.111.96.233 - # netbiLgini ~ en hızLı büyüyen forum...url
c:\documents and settings\Admin\Sık Kullanılanlar\POWER TURK - ONCE MUZIK....url
c:\windows\remote.ini
.
((((((((((((((((((((((((( Files Created from 2010-07-22 to 2010-08-22 )))))))))))))))))))))))))))))))
.
2010-08-22 21:59 . 2010-08-22 21:59 -------- d-----w- C:\Dell
2010-08-22 16:17 . 2010-08-22 16:17 -------- d-----w- c:\documents and settings\All Users\Uniblue
2010-08-22 15:43 . 2010-08-22 16:13 -------- d-----w- c:\documents and settings\Admin\Application Data\Uniblue
2010-08-22 15:43 . 2010-08-22 16:16 -------- d-----w- c:\program files\Uniblue
2010-08-22 15:31 . 2010-08-22 15:32 -------- d-----w- c:\program files\Realtek AC97
2010-08-22 11:14 . 2003-07-01 20:42 27904 ----a-w- c:\windows\system32\drivers\VIAAGP1.SYS
2010-08-22 11:00 . 2004-04-15 10:57 42496 ----a-w- c:\windows\system32\drivers\fetnd5b.sys
2010-08-22 11:00 . 2003-07-17 16:10 7040 ----a-w- c:\windows\system32\ntsim.sys
2010-08-22 10:54 . 2010-08-22 10:54 -------- d-----w- c:\program files\Realtek Sound Manager
2010-08-22 10:54 . 2010-08-22 15:32 -------- d-----w- c:\program files\AvRack
2010-08-22 01:33 . 2004-07-12 08:50 241664 ----a-r- c:\windows\system32\nvwrshe.dll
2010-08-22 01:22 . 2010-08-22 01:22 -------- d-----w- c:\documents and settings\All Users\Application Data\UAB
2010-08-22 01:22 . 2010-08-22 01:22 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\PC_Drivers_Headquarters
2010-08-22 01:20 . 2010-08-22 01:20 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\eSupport.com
2010-08-22 01:20 . 2010-08-22 01:20 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2010-08-22 00:12 . 2010-03-30 20:38 20968 ----a-w- c:\windows\system32\drivers\cpuz133_x32.sys
2010-08-22 00:12 . 2010-08-22 00:12 -------- d-----w- c:\program files\CPUID
2010-08-21 10:27 . 2010-08-21 21:08 -------- d-----w- c:\windows\NV29803720.TMP
2010-08-20 23:05 . 2004-07-12 08:50 147456 ----a-r- c:\windows\system32\nvwrszht.dll
2010-08-20 23:05 . 2004-07-12 08:50 86016 ----a-r- c:\windows\system32\nvrszht.dll
2010-08-20 23:05 . 2004-07-12 08:50 172032 ----a-r- c:\windows\system32\nvrszhc.dll
2010-08-20 23:05 . 2004-07-12 08:50 143360 ----a-r- c:\windows\system32\nvwrszhc.dll
2010-08-20 23:05 . 2004-07-12 08:50 266240 ----a-r- c:\windows\system32\nvwrstr.dll
2010-08-20 23:05 . 2004-07-12 08:50 176128 ----a-r- c:\windows\system32\nvrstr.dll
2010-08-20 23:05 . 2004-07-12 08:50 258048 ----a-r- c:\windows\system32\nvwrssv.dll
2010-08-20 23:05 . 2004-07-12 08:50 172032 ----a-r- c:\windows\system32\nvrssv.dll
2010-08-20 23:05 . 2004-07-12 08:50 262144 ----a-r- c:\windows\system32\nvwrssl.dll
2010-08-20 23:04 . 2004-07-12 08:50 172032 ----a-r- c:\windows\system32\nvrssl.dll
2010-08-20 23:04 . 2004-07-12 08:50 258048 ----a-r- c:\windows\system32\nvwrssk.dll
2010-08-20 23:04 . 2004-07-12 08:50 172032 ----a-r- c:\windows\system32\nvrssk.dll
2010-08-20 23:04 . 2004-07-12 08:50 274432 ----a-r- c:\windows\system32\nvwrsru.dll
2010-08-20 23:04 . 2004-07-12 08:50 184320 ----a-r- c:\windows\system32\nvrsru.dll
2010-08-20 23:04 . 2010-08-20 23:07 -------- d-----w- c:\windows\NV24522300.TMP
2010-08-20 23:02 . 2004-07-12 08:50 3740032 -c--a-w- c:\windows\system32\dllcache\nv4_disp.dll
2010-08-20 23:02 . 2004-07-12 08:50 3740032 ----a-r- c:\windows\system32\nv4_disp.dll
2010-08-20 23:02 . 2004-07-12 08:50 2459968 -c--a-w- c:\windows\system32\dllcache\nv4_mini.sys
2010-08-20 23:02 . 2004-07-12 08:50 2459968 ----a-r- c:\windows\system32\drivers\nv4_mini.sys
2010-08-20 22:45 . 2001-11-08 14:37 221184 ----a-w- c:\windows\system32\Dualunis.exe
2010-08-20 22:45 . 1999-12-07 01:00 40592 ----a-r- c:\windows\system32\stream.sys
2010-08-20 22:44 . 2000-07-18 07:41 221184 ----a-w- c:\windows\system32\SP5X_32.DLL
2010-08-20 22:44 . 2000-01-04 23:17 24576 ----a-w- c:\windows\system32\Ca500Ext.dll
2010-08-20 22:44 . 2001-01-03 09:06 148385 ----a-w- c:\windows\system32\drivers\CA500AV.SYS
2010-08-20 22:44 . 2001-01-03 09:06 10810 ----a-w- c:\windows\system32\drivers\minbulk.sys
2010-08-16 08:44 . 2010-08-16 08:44 103424 ----a-w- c:\windows\system32\DCLibrary_nat.dll
2010-08-15 23:01 . 2010-08-15 23:01 -------- d-----w- c:\program files\S3
2010-08-15 23:01 . 2004-10-05 13:54 306688 ----a-w- c:\windows\IsUninst.exe
2010-08-15 23:01 . 2010-08-15 23:01 -------- d-----w- c:\documents and settings\Admin\WINDOWS
2010-08-15 22:09 . 2010-08-15 22:09 -------- d-----w- c:\program files\Driver-Soft
2010-08-15 22:07 . 2010-08-15 22:07 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2010-08-15 22:01 . 2010-08-15 22:01 -------- d-----w- c:\program files\PC Drivers HeadQuarters
2010-08-15 19:14 . 2010-08-22 21:20 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-08-15 18:44 . 2010-08-16 11:09 -------- d-----w- c:\documents and settings\Admin\Local Settings\Application Data\Conduit
2010-08-15 18:44 . 2010-08-15 18:44 -------- d-----w- c:\program files\Conduit
2010-08-15 15:48 . 2010-08-15 15:48 -------- d-----w- c:\windows\system32\wbem\Repository
2010-08-15 11:36 . 2010-08-15 11:36 -------- d-----w- c:\windows\system32\NVRTClk
2010-08-15 11:36 . 2003-12-30 09:44 24576 ----a-r- c:\windows\system32\NVRTClk.exe
2010-08-15 11:36 . 2003-05-15 14:44 40960 ----a-r- c:\windows\system32\NVGPIO.dll
2010-08-15 10:33 . 2010-08-15 10:33 -------- d-----w- c:\program files\Lavalys
2010-08-09 21:16 . 2010-08-09 21:16 -------- d-----w- c:\program files\Ventrilo
2010-08-05 01:34 . 2010-08-05 01:34 -------- d-----r- c:\documents and settings\ko1\Sık Kullanılanlar
2010-08-05 01:34 . 2010-08-08 12:16 -------- d-----w- c:\documents and settings\ko1
2010-07-24 15:27 . 2010-07-24 15:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-22 16:14 . 2010-08-22 16:13 5268200 ----a-w- c:\documents and settings\Admin\Application Data\Uniblue\DriverScanner\_temp\driverscanner.exe
2010-08-22 16:14 . 2010-08-22 16:13 5276232 ----a-w- c:\documents and settings\Admin\Application Data\Uniblue\SpeedUpMyPC\_temp\sump.exe
2010-08-22 15:06 . 2010-08-22 15:06 20133 ----a-w- c:\windows\system32\drivers\isapnp.rar
2010-08-21 22:23 . 2008-07-31 00:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2010-08-18 21:02 . 2009-07-17 19:50 -------- d-----w- c:\program files\Vindir for YouTube 3
2010-08-16 21:53 . 2010-01-29 20:12 -------- d-----w- c:\documents and settings\Admin\Application Data\DivX
2010-08-15 23:18 . 2007-06-07 18:00 -------- d-sh--w- c:\program files\SystemRequirementsLab
2010-08-15 23:18 . 2009-01-24 16:40 -------- d-----w- c:\documents and settings\Admin\Application Data\SystemRequirementsLab
2010-08-15 23:18 . 2010-08-15 23:18 290816 ----a-w- c:\documents and settings\Admin\Application Data\SystemRequirementsLab\SRLProxy_nvd_4.dll
2010-08-15 23:18 . 2010-08-15 23:18 290816 ----a-w- c:\documents and settings\Admin\Application Data\SystemRequirementsLab\SRLProxy_nvd_3.dll
2010-08-15 23:18 . 2010-08-15 23:18 290816 ----a-w- c:\documents and settings\Admin\Application Data\SystemRequirementsLab\SRLProxy_nvd_2.dll
2010-08-15 23:18 . 2010-08-15 23:18 290816 ----a-w- c:\documents and settings\Admin\Application Data\SystemRequirementsLab\SRLProxy_nvd_1.dll
2010-08-15 23:01 . 2006-08-27 12:38 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-08-14 22:37 . 2008-09-26 10:57 -------- d-----w- c:\program files\PC Connectivity Solution
2010-08-12 15:46 . 2001-11-22 12:00 76934 ----a-w- c:\windows\system32\perfc01F.dat
2010-08-12 15:46 . 2001-11-22 12:00 419904 ----a-w- c:\windows\system32\perfh01F.dat
2010-08-11 10:47 . 2010-08-15 11:44 305378 ----a-w- c:\windows\PCHealth\HelpCtr\Config\Cache\Professional_32_1055.dat
2010-08-09 21:26 . 2008-08-09 15:47 -------- d-----w- c:\documents and settings\Admin\Application Data\Ventrilo
2010-08-09 21:15 . 2009-01-03 20:41 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-07-28 13:26 . 2007-06-06 18:04 -------- d-sh--w- c:\program files\sXe Injected
2010-07-28 08:52 . 2009-01-26 22:05 -------- d-----w- c:\documents and settings\Admin\Application Data\TeamViewer
2010-07-27 10:24 . 2007-01-17 18:09 -------- d-----w- c:\documents and settings\Admin\Application Data\LimeWire
2010-07-25 20:43 . 2010-07-25 08:26 198557 ----a-w- c:\documents and settings\Admin\Application Data\appdata.dll
2010-07-25 20:43 . 2010-07-25 08:26 198557 ----a-w- c:\documents and settings\Admin\Application Data\appdata.dll
2010-07-24 16:03 . 2009-09-07 12:02 -------- d-----w- c:\program files\Common Files\Adobe
2010-07-24 15:27 . 2010-07-06 01:52 -------- d-----w- c:\program files\Alwil Software
2010-07-23 15:58 . 2010-07-23 15:58 552 ----a-w- c:\windows\system32\d3d8caps.dat
2010-07-18 00:13 . 2009-01-07 12:03 -------- d-----w- c:\documents and settings\Admin\Application Data\Winamp
2010-07-17 23:46 . 2009-11-24 09:29 -------- d-----w- c:\program files\Winamp Toolbar
2010-07-16 17:49 . 2010-07-16 17:05 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-07-16 17:44 . 2010-01-29 19:48 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-07-16 17:43 . 2010-07-16 17:43 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
2010-07-16 17:19 . 2010-01-29 19:48 -------- d-----w- c:\program files\DivX
2010-07-05 21:51 . 2010-07-05 21:46 -------- d-----w- c:\program files\Creative
2010-07-05 21:50 . 2010-07-05 21:48 -------- d--h--w- c:\program files\Creative Installation Information
2010-07-05 21:48 . 2010-07-05 21:48 -------- d-----w- c:\program files\Common Files\Creative
2010-07-05 21:07 . 2010-03-05 23:02 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-06-30 12:32 . 2002-10-01 08:03 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-30 11:22 . 2010-06-30 11:22 52224 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\qh9kypf8.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\components\FFExternalAlert.dll
2010-06-30 11:22 . 2010-06-30 11:22 101376 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\qh9kypf8.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\components\RadioWMPCore.dll
2010-06-24 12:24 . 2002-10-01 08:04 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 09:02 . 2002-10-01 07:57 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2001-11-22 12:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2001-11-22 12:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2006-08-27 12:10 744448 ----a-w- c:\windows\PCHealth\HelpCtr\Binaries\helpsvc.exe
2010-06-14 07:42 . 2002-10-01 08:03 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-09 08:06 . 2010-06-09 08:06 976832 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\2712\AdobeARM.exe
2010-06-09 08:06 . 2010-06-09 08:06 70584 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\2712\AdobeExtractFiles.dll
2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\2712\ReaderUpdater.exe
2010-06-09 08:06 . 2010-06-09 08:06 331176 ----a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.3\ARM\2712\AcrobatUpdater.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"RegistryBooster"="c:\program files\Uniblue\RegistryBooster\launcher.exe" [2010-07-27 67456]
"DriverScanner"="c:\program files\Uniblue\DriverScanner\launcher.exe" [2010-07-16 338296]
"SpeedUpMyPC"="c:\program files\Uniblue\SpeedUpMyPC\launcher.exe" [2010-06-25 67960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRTCLK"="c:\windows\system32\NVRTCLK\NVRTClk.exe" [2003-12-30 24576]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-07-12 4112384]
"nwiz"="nwiz.exe" [2004-07-12 843776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2004-07-12 81920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"Nokia.PCSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2007-03-27 1744896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 16:00 15360 ------w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 14:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVRTCLK]
2003-12-30 09:44 24576 ----a-r- c:\windows\system32\NVRTClk\NVRTClk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\English\\setup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\Warcraft III\\war3.exe"=
"c:\\Program Files\\BearShare Applications\\BearShare\\BearShare.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [01.02.2008 18:24 41456]
R2 cpuz133;cpuz133;c:\windows\system32\drivers\cpuz133_x32.sys [22.08.2010 03:12 20968]
R3 CnxEtP;ADSL USB MODEM WAN Adapter Filter Driver;c:\windows\system32\drivers\CnxEtP.sys [28.07.2008 13:10 60288]
R3 CnxEtU;ADSL USB MODEM Loader;c:\windows\system32\drivers\CnxEtU.sys [28.07.2008 13:10 646400]
R3 CnxTgN;ADSL USB MODEM WAN Adapter Driver;c:\windows\system32\drivers\CnxTgN.sys [28.07.2008 13:10 108771]
S0 ddvqknkx;ddvqknkx;c:\windows\system32\drivers\gugchoe.sys --> c:\windows\system32\drivers\gugchoe.sys
S0 wtpogoe;wtpogoe;c:\windows\system32\drivers\wtyvtred.sys --> c:\windows\system32\drivers\wtyvtred.sys
S2 gupdate1caa11c119880a6;Google Güncelleme Hizmeti (gupdate1caa11c119880a6);c:\program files\Google\Update\GoogleUpdate.exe [29.01.2010 22:48 133104]
S2 WallHack;WallHack;\??\c:\documents and settings\Admin\Desktop\fdg\sxe7.7-WH_-_CeVDeToR\sxe7.7-WH_-_CeVDeToR\sxe7.7-WH - CeVDeToR\WallHack.sys --> c:\documents and settings\Admin\Desktop\fdg\sxe7.7-WH_-_CeVDeToR\sxe7.7-WH_-_CeVDeToR\sxe7.7-WH - CeVDeToR\WallHack.sys
S3 APR;APR;\??\d:\knightonline\APR.sys --> d:\knightonline\APR.sys
S3 CAM1690;USB 2.0 Compliance JPEG Video Camera;c:\windows\system32\drivers\cam1690.sys [29.08.2007 12:01 153344]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [22.08.2010 04:20 23456]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [03.08.2005 00:10 32512]
S3 vvftav303;vvftav303;c:\windows\system32\drivers\vvftav303.sys [31.07.2008 13:04 480128]
S3 XDva002;XDva002;\??\c:\windows\system32\XDva002.sys --> c:\windows\system32\XDva002.sys
S3 XDva007;XDva007;\??\c:\windows\system32\XDva007.sys --> c:\windows\system32\XDva007.sys
S3 XDva009;XDva009;\??\c:\windows\system32\XDva009.sys --> c:\windows\system32\XDva009.sys
S3 XDva010;XDva010;\??\c:\windows\system32\XDva010.sys --> c:\windows\system32\XDva010.sys
S3 XDva012;XDva012;c:\windows\system32\XDva012.sys [10.06.2007 17:11 15115]
S3 XDva013;XDva013;\??\c:\windows\system32\XDva013.sys --> c:\windows\system32\XDva013.sys
S3 XDva014;XDva014;\??\c:\windows\system32\XDva014.sys --> c:\windows\system32\XDva014.sys
S3 XDva016;XDva016;\??\c:\windows\system32\XDva016.sys --> c:\windows\system32\XDva016.sys
S3 XDva020;XDva020;\??\c:\windows\system32\XDva020.sys --> c:\windows\system32\XDva020.sys
S3 XDva025;XDva025;\??\c:\windows\system32\XDva025.sys --> c:\windows\system32\XDva025.sys
S3 XDva031;XDva031;\??\c:\windows\system32\XDva031.sys --> c:\windows\system32\XDva031.sys
S3 XDva033;XDva033;\??\c:\windows\system32\XDva033.sys --> c:\windows\system32\XDva033.sys
S3 XDva062;XDva062;\??\c:\windows\system32\XDva062.sys --> c:\windows\system32\XDva062.sys
S3 XDva078;XDva078;\??\c:\windows\system32\XDva078.sys --> c:\windows\system32\XDva078.sys
S3 XDva089;XDva089;\??\c:\windows\system32\XDva089.sys --> c:\windows\system32\XDva089.sys
S3 XDva090;XDva090;\??\c:\windows\system32\XDva090.sys --> c:\windows\system32\XDva090.sys
S3 XDva136;XDva136;\??\c:\windows\system32\XDva136.sys --> c:\windows\system32\XDva136.sys
S3 ZSMC0303;A4 TECH PC Camera H;c:\windows\system32\Drivers\usbVM303.sys --> c:\windows\system32\Drivers\usbVM303.sys
.
Contents of the 'Scheduled Tasks' folder
2010-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 19:48]
2010-08-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 19:48]
2010-07-16 c:\windows\Tasks\Install_NSS.job
- c:\program files\DivX\Symantec\scstubinstaller.exe [2010-03-08 18:00]
2010-08-22 c:\windows\Tasks\RegistryBooster.job
- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2010-08-22 08:11]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.tr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = about:blank
mLocal Page = hxxp://www.Google.com/
mSearch Bar = hxxp://www.Google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
TCP: interfaces = 208.67.222.222,208.67.220.220
TCP: {274CB58D-67F6-4CC4-963B-43388B846157} = 4.2.2.2 4.2.2.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\qh9kypf8.defaultFF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2077543&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - ToggleEN Customized Web Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.tr/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampab&query=
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\qh9kypf8.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\qh9kypf8.default\extensions\{038cb5c7-48ea-4af9-94e0-a1646542e62b}\components\RadioWMPCore.dll
FF - component: c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\qh9kypf8.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\components\WinampTBPlayer.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[email]linkfilter@kaspersky.ru[/email]\components\kavlinkfilter.dll
FF - plugin: c:\documents and settings\Admin\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-DLLHost - c:\documents and settings\Admin\Application Data\dllhost.exe
MSConfigStartUp-rundll - c:\documents and settings\Admin\Application Data\rundll.exe
ActiveSetup-{735EC9A1-7DE0-D0B4-920F-36EE78E89BAE} - c:\windows\system32:windowsupta.exe
AddRemove-Adobe Flash Player Plugin - c:\windows\system32\Macromed\Flash\FlashUtil10h_Plugin.exe
AddRemove-Counter-Strike 1.5 Türkçe Paketi - c:\sierra\HALF-L~1\UNWISE.EXE
AddRemove-Half-Life - c:\sierra\HALF-L~1\UNWISE.EXE
AddRemove-PhotoScape - c:\program files\PhotoScape\uninstall.exe
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-23 02:38
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2000478354-861567501-839522115-1003\Software\Microsoft\MessengerService\GroupStateCacheU\Aq*]
"Name"=hex:41,01,71,00,00,00
"Collapsed"=hex:00,00,00,00
[HKEY_USERS\S-1-5-21-2000478354-861567501-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*^]
@Class="Shell"
[HKEY_USERS\S-1-5-21-2000478354-861567501-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*^\OpenWithList]
@Class="Shell"
"a"="firefox.exe"
"MRUList"="a"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):67,6f,a0,bb,ab,2a,3f,dd,37,98,46,40,78,d4,82,07,49,ef,bf,a6,8e,
99,05,b6,02,8a,e5,e6,b6,f4,54,82,f7,a6,28,db,65,50,e2,9f,00,00,00,00,00,00,
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8b75b49f-d2c4-4b58-9380-cebf0b3bb07d}]
@Denied: (Full) (Everyone)
"Model"=dword:00000061
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•6~*]
"??????ª??????????"=multi:"î?€MZ\00\03\00\00\00\04\00\00\00ÿÿ\00\00¸\00\00\00\00\00\00\00@\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00ø\00\00\00\0e\1fº\0e\00´\09Í!¸\01LÍ!This program cannot be run in DOS mode.\0d\0d\0a$\00\00\00\00\00\00\00›w{ïß\16\15¼ß\16\15¼ß\16\15¼øĞx¼Ş\16\15¼øĞ{¼Ş\16\15¼\1c\19H¼Ò\16\15¼ß\16\14¼|\16\15¼oÓh¼Â\16\15¼oÓx¼v\00\00"
.
Completion time: 2010-08-23 02:44:06
ComboFix-quarantined-files.txt 2010-08-22 23:43
ComboFix2.txt 2010-03-07 20:58
Pre-Run: 499.552.256 bayt boş
Post-Run: 6.537.359.360 bayt boş
- - End Of File - - C99AEB258E55DB13293020F69BAC77CE
Buda Hijackthis Analiz Rapor'um
Logfile of Advanced SystemCare 3 Security Analyzer
Scan saved at 03:34:14, on 23.08.2010
Platform: Windows XP (WinNT 5.1)
MSIE: Internet Explorer v8.0 (8.0.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [RegistryBooster] "C:\Program Files\Uniblue\RegistryBooster\launcher.exe" delay 20000
O4 - HKCU\..\Run: [DriverScanner] "C:\Program Files\Uniblue\DriverScanner\launcher.exe" delay 20000
O4 - HKCU\..\Run: [SpeedUpMyPC] "C:\Program Files\Uniblue\SpeedUpMyPC\launcher.exe" delay 20000
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKLM\..\Run: [NVRTCLK] C:\WINDOWS\system32\NVRTCLK\NVRTClk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0 ... 11-windows-i586.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - http://fpdownload.macromedia.com ... rbear/ultrashim.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bi ... Client.cab56907.cab
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) - http://java.sun.com/update/1.6.0 ... 07-windows-i586.cab
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0 ... 11-windows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0 ... 11-windows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.co ... s/flash/swflash.cab
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Google Güncelleme Hizmeti (gupdate1caa11c119880a6) (gupdate1caa11c119880a6) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Unknown - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown - %ProgramFiles%\WinPcap\rpcapd.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
YARDIMLARINIZI BEKLİYORUM.Teşekkürler.